메뉴 건너뛰기




Volumn , Issue , 2010, Pages 1-269

Design and Safety Assessment of Critical Systems

Author keywords

[No Author keywords available]

Indexed keywords


EID: 85134933282     PISSN: None     EISSN: None     Source Type: Book    
DOI: 10.1201/b10094     Document Type: Book
Times cited : (64)

References (357)
  • 1
    • 36448976990 scopus 로고    scopus 로고
    • Air Force Safety Agency (2000). Air Force System Safety Handbook. Available at http://www.system-safety.org/Documents/AF_System-Safety-HNDBK.pdf. Last retrieved on November, 15, 2009.
    • (2000) Air Force System Safety Handbook
  • 3
    • 0000175192 scopus 로고
    • Safety-critical systems, formal methods and standards
    • Bowen, J.P. and V. Stavridou (1992). Safety-critical systems, formal methods and standards. BCS/IEE Software Engineering Journal 8(4), 189–209.
    • (1992) BCS/IEE Software Engineering Journal , vol.8 , Issue.4 , pp. 189-209
    • Bowen, J.P.1    Stavridou, V.2
  • 6
    • 20044368093 scopus 로고    scopus 로고
    • ESACS: An integrated methodology for design and safety analysis of complex systems
    • Leiden, The Netherlands: Balkema
    • Bozzano, M., A. Villafiorita, and O. Åkerlund et al. (2003). ESACS: An integrated methodology for design and safety analysis of complex systems. In Proc. European Safety and Reliability Conference (ESREL 2003), pp. 237–245. Leiden, The Netherlands: Balkema.
    • (2003) Proc. European Safety and Reliability Conference (ESREL 2003) , pp. 237-245
    • Bozzano, M.1    Villafiorita, A.2    Åkerlund, O.3
  • 11
    • 65749098082 scopus 로고    scopus 로고
    • Embedded software: Facts, figures, and future
    • Ebert, C. and C. Jones (2009). Embedded software: Facts, figures, and future. Computer 42(04), 42–52.
    • (2009) Computer , vol.42 , Issue.4 , pp. 42-52
    • Ebert, C.1    Jones, C.2
  • 13
    • 84882934448 scopus 로고    scopus 로고
    • A short history of system safety
    • Ericson II C.A. (2006). A short history of system safety. Journal of System Safety (eEdition) 42(3).
    • (2006) Journal of System Safety , vol.42 , Issue.3
    • Ericson, C.A.1
  • 15
    • 0035393057 scopus 로고    scopus 로고
    • Crouching dragon, hidden software: Software in DoD weapon systems
    • Ferguson, J. (2001). Crouching dragon, hidden software: Software in DoD weapon systems. IEEE Software 18(4), 105–107.
    • (2001) IEEE Software , vol.18 , Issue.4 , pp. 105-107
    • Ferguson, J.1
  • 17
    • 85134995680 scopus 로고    scopus 로고
    • History of the Elevator (Last retrieved on November 15, 2009). The History of the Elevator. Available at http://inventors.about.com/library/inventors/blelevator.htm.
    • (2009) The History of the Elevator
  • 20
    • 0005070779 scopus 로고
    • Architectural blueprints—the “4+1” view model of software architecture
    • Kruchten, P. (1995). Architectural blueprints—the “4+1” view model of software architecture. IEEE Software 12(6), 44–50.
    • (1995) IEEE Software , vol.12 , Issue.6 , pp. 44-50
    • Kruchten, P.1
  • 21
    • 84947240651 scopus 로고
    • Fly-by-wire systems for military high performance aircraft
    • M. Schiebe and S. Pferrer (Eds.), Dordrecht, The Netherlands. Kluwer Academic
    • Langer, D., J. Rauch, and M. Rössler (1992). Fly-by-wire systems for military high performance aircraft. In M. Schiebe and S. Pferrer (Eds.), Real-Time Systems Engineering and Applications, pp. 369–395. Dordrecht, The Netherlands. Kluwer Academic.
    • (1992) Real-Time Systems Engineering and Applications , pp. 369-395
    • Langer, D.1    Rauch, J.2
  • 23
    • 0003533985 scopus 로고    scopus 로고
    • Washington, D.C.: IEEE Computer Society, and New York: McGraw-Hill
    • Lyu, M.R. (Ed.) (1996). Handbook of Software Reliability Engineering. Washington, D.C.: IEEE Computer Society, and New York: McGraw-Hill.
    • (1996) Handbook of Software Reliability Engineering
    • Lyu, M.R.1
  • 24
  • 25
    • 0000793139 scopus 로고
    • Cramming more components onto integrated circuits
    • Moore, G.E. (1965). Cramming more components onto integrated circuits. Electronics 38(8), 114–117.
    • (1965) Electronics , vol.38 , Issue.8 , pp. 114-117
    • Moore, G.E.1
  • 26
    • 85134929673 scopus 로고    scopus 로고
    • NASA (Last retrieved on November, 15, 2009). F-8 digital fly-by-wire aircraft. Available at http://www.nasa.gov/centers/dryden/news/FactSheets/FS-024-DFRC.html.
    • (2009) F-8 Digital Fly-By-Wire Aircraft
  • 27
    • 85134985970 scopus 로고    scopus 로고
    • Practical Reliability Engineering
    • New York: Wiley. Quantitative Software Management, Inc.
    • O’Connor, P.D. (2003). Practical Reliability Engineering (4th ed.). New York: Wiley. Quantitative Software Management, Inc. (Last retrieved on November 15, 2009). Function Point Languages table. Available at http://www.qsm.com/?q=resources/function-point-languages-table/index.html.
    • (2003) Function Point Languages Table
    • O’Connor, P.D.1
  • 30
    • 85134924811 scopus 로고    scopus 로고
    • Behring Center
    • Smithsonian National Museum of American History, Behring Center (Last retrieved on November 15, 2009). Three Mile Island: The Inside Story. Available at http://americanhistory.si.edu/TMI/.
    • (2009) Three Mile Island: The inside Story
  • 33
    • 79959325008 scopus 로고    scopus 로고
    • U.S. Nuclear Regulatory Commission (Last retrieved on November 15, 2009). Backgrounder on the Three Mile Island Accident. Available at http://www.nrc.gov/readingrm/doc-collections/fact-sheets/3mile-isle.html.
    • (2009) Backgrounder on the Three Mile Island Accident
  • 34
    • 85134920340 scopus 로고    scopus 로고
    • World Nuclear Industry Handbook
    • Kenf, Surrey, England: Business Press International
    • Various Authors (2007). World Nuclear Industry Handbook. Kenf, United Kingdom: Nuclear Engineering International. Surrey, England: Business Press International.
    • (2007) United Kingdom: Nuclear Engineering International
  • 35
    • 85134933066 scopus 로고    scopus 로고
    • Various Authors (Last retrieved on November, 15, 2009). Aircraft Flight Control System: Available at http://en.wikipedia.org/wiki/Aircraft_flight_control_systems.
    • (2009) Aircraft Flight Control System
  • 38
    • 77951726044 scopus 로고    scopus 로고
    • World Nuclear Association (Last retrieved on November 15, 2009). Nuclear Power Reactors. Available at http://www.world-nuclear.org/info/inf32.html.
    • (2009) Nuclear Power Reactors
  • 40
    • 85134897822 scopus 로고    scopus 로고
    • FSAP (Last retrieved on November 15, 2009). The FSAP/NuSMV-SA Platform. Available at https://es.fbk.eu/tools/FSAP.
    • (2009) The Fsap/Nusmv-Sa Platform
  • 41
    • 85134981711 scopus 로고    scopus 로고
    • Gonyeau, J. (2009). Chernobyl Event. Available at http://www.nucleartourist.com/. Last retrieved on November 15, 2009.
    • (2009) Chernobyl Event
    • Gonyeau, J.1
  • 42
    • 85134937137 scopus 로고    scopus 로고
    • Griffin, S. (2009). Internet Pioneers. Available at http://www.ibiblio.org/pioneers/index.html. Last retrieved on November 15, 2009.
    • (2009) Internet Pioneers
    • Griffin, S.1
  • 45
    • 37249090610 scopus 로고    scopus 로고
    • Voting structures for cascaded triple modular redundant modules
    • Lee, S., J.-il Jung, and I. Lee (2007). Voting structures for cascaded triple modular redundant modules. IEICE Electronics Express 4(21), 657.
    • (2007) IEICE Electronics Express , vol.4 , Issue.21 , pp. 657
    • Lee, S.1    Jung, J.-I.2    Lee, I.3
  • 46
    • 37249038760 scopus 로고    scopus 로고
    • Staggered voting for TMR shift register chains in poly-Si TFT-LCDs
    • Lee, S. and I. Lee (2001). Staggered voting for TMR shift register chains in poly-Si TFT-LCDs. Journal of Information Display 2(2), 22–26.
    • (2001) Journal of Information Display , vol.2 , Issue.2 , pp. 22-26
    • Lee, S.1    Lee, I.2
  • 49
    • 85010248741 scopus 로고
    • Reliable circuits using less reliable relays
    • Moore, E.F. and C.E. Shannon (1956). Reliable circuits using less reliable relays. Journal of the Franklin Institute 262, 191–208 and 281–297.
    • (1956) Journal of the Franklin Institute , vol.262 , pp. 191-208
    • Moore, E.F.1    Shannon, C.E.2
  • 54
    • 84977085189 scopus 로고    scopus 로고
    • Various Authors (2009a). Chernobyl disaster. Available at http://en.wikipedia.org/w/index.php?title=Chernobyl_disaster. Last retrieved on November 15, 2009.
    • (2009) Chernobyl Disaster
  • 55
    • 78149387408 scopus 로고    scopus 로고
    • Various Authors (2009b). The history of the internet. Available at http://en.wikipedia.org/wiki/History_of_the_Internet. Last retrieved on November 15, 2009.
    • (2009) The History of the Internet
  • 56
    • 0003133883 scopus 로고
    • Probabilistic logics and the synthesis of reliable organisms from unreliable components
    • In C.E. Shannon and J. McCarthy (Eds.), Princeton, NJ: Princeton University Press
    • Von Neumann, J. (1956). Probabilistic logics and the synthesis of reliable organisms from unreliable components. In C.E. Shannon and J. McCarthy (Eds.), Automata Studies, Number 34, pp. 43–98. Princeton, NJ: Princeton University Press.
    • (1956) Automata Studies , vol.34 , pp. 43-98
    • von Neumann, J.1
  • 57
    • 85134931878 scopus 로고
    • The reliability and safety assessment of protection systems by the use of dynamic event trees
    • Proc. XVIII Annual Meeting Spanish Nuclear Society
    • Cojazzi, G., J.M. Izquierdo, E. Melèndez, and M.S. Perea (1992). The reliability and safety assessment of protection systems by the use of dynamic event trees. The DYLAM-TRETA package. In Proc. XVIII Annual Meeting Spanish Nuclear Society.
    • (1992) The DYLAM-TRETA Package
    • Cojazzi, G.1    Izquierdo, J.M.2    Melèndez, E.3    Perea, M.S.4
  • 58
    • 0026925395 scopus 로고
    • Dynamic fault-tree models for fault-tolerant computer systems
    • Dugan, J., S. Bavuso, and M. Boyd (1992). Dynamic fault-tree models for fault-tolerant computer systems. IEEE Transactions on Reliability 41(3), 363–377.
    • (1992) IEEE Transactions on Reliability , vol.41 , Issue.3 , pp. 363-377
    • Dugan, J.1    Bavuso, S.2    Boyd, M.3
  • 62
    • 8344227046 scopus 로고    scopus 로고
    • Guidelines and Methods for Conducting the Safety Assessment Process on Civil Airborne Systems and Equipment
    • SAE (1996). Guidelines and Methods for Conducting the Safety Assessment Process on Civil Airborne Systems and Equipment. Technical Report ARP4761, Society of Automotive Engineers.
    • (1996) Technical Report ARP4761, Society of Automotive Engineers
  • 64
    • 85134898565 scopus 로고    scopus 로고
    • Defence Standard 00-56. Safety Management Requirements for Defence Systems
    • U.K. Ministry of Defence
    • U.K. Ministry of Defence (2007). Defence Standard 00-56. Safety Management Requirements for Defence Systems. Part I: Requirements. II. Guidance on Establishing a Means of Complying with Part 1. U.K. Ministry of Defence.
    • (2007) Guidance on Establishing a Means of Complying with Part 1
  • 67
    • 38349042923 scopus 로고    scopus 로고
    • AIA, GAMA, and FAA Aircraft Certification Service (2004). The FAA and Industry Guide to Product Certification. Available at http://www.faa.gov/aircraft/air_cert/design_approvals/media/CPI_guide_II.pdf. Last retrieved on November 15, 2009.
    • (2004) The FAA and Industry Guide to Product Certification
  • 68
    • 85134916941 scopus 로고    scopus 로고
    • AIRBUS (Last retrieved on November 15, 2009). A380 Family. Available at http://www.airbus.com/en/aircraftfamilies/a380/.
    • (2009) A380 Family
  • 69
    • 0002925854 scopus 로고
    • Measuring application development productivity
    • Indianapolis, IN: IBM Press
    • Albrecht, A.J. (1979). Measuring application development productivity. In Proc. IBM Application Development Symposium, pp. 83–92. Indianapolis, IN: IBM Press.
    • (1979) Proc. IBM Application Development Symposium , pp. 83-92
    • Albrecht, A.J.1
  • 72
    • 84889553404 scopus 로고
    • Bell Canada (1994). The Trillium Model. Available at http://www2.umassd.edu/swpi/BellCanada/trillium-html/trillium.html. Last retrieved on November 15, 2009.
    • (1994) The Trillium Model
  • 74
    • 0024012763 scopus 로고
    • A spiral model of software development and enhancement
    • Boehm, B.W. (1988). A spiral model of software development and enhancement. IEEE Computer 21(5), 61–72.
    • (1988) IEEE Computer , vol.21 , Issue.5 , pp. 61-72
    • Boehm, B.W.1
  • 81
    • 0011790817 scopus 로고    scopus 로고
    • Capability Maturity Model Integration
    • Pittsburgh, PA: Software Engineering Institute
    • CMMI Product Team (2009). Capability Maturity Model Integration. Technical Report CMU/SEI-2006-TR-008. Pittsburgh, PA: Software Engineering Institute.
    • (2009) Technical Report CMU/SEI-2006-TR-008
  • 82
    • 0003682013 scopus 로고    scopus 로고
    • COCOMO II (2000). COCOMO II Model Definition Manual. Available at http://csse.usc.edu/csse/research/COCOMOII/cocomo2000.0/CII_modelman2000.0.pdf. Last retrieved on November 15, 2009.
    • (2000) COCOMO II Model Definition Manual
  • 84
  • 85
    • 77953220742 scopus 로고    scopus 로고
    • Technical Report CMU/SEI-2007-TN-006, Pittsburgh, PA: Software Engineering Institute
    • Defence Materiel Organisation, Australian Department of Defence (2007). +SAFE, V1.2: A Safety Extension to CMMI-DEV, V1.2. Technical Report CMU/SEI-2007-TN-006, Pittsburgh, PA: Software Engineering Institute.
    • (2007) A Safety Extension to CMMI-DEV , vol.V1 , Issue.2
  • 86
    • 85134897722 scopus 로고
    • Military Standard—System Safety Program Requirements
    • Department of Defense (1993). Military Standard—System Safety Program Requirements. Technical Report MIL-STD-882C, Department of Defense.
    • (1993) Technical Report MIL-STD-882C, Department of Defense
  • 87
    • 85134919884 scopus 로고    scopus 로고
    • Department of Defense Handbook—Work Breakdown Structure
    • Department of Defense (1998). Department of Defense Handbook—Work Breakdown Structure. Technical Report MIL-HDBK-881, Department of Defense.
    • (1998) Technical Report MIL-HDBK-881, Department of Defense
  • 88
    • 85134965937 scopus 로고    scopus 로고
    • Department of Defence, Standard Practice for System Safety
    • Department of Defense (2000). Department of Defence, Standard Practice for System Safety. Technical Report MIL-STD-882D, Department of Defense.
    • (2000) Technical Report MIL-STD-882D, Department of Defense
  • 90
    • 77958490741 scopus 로고    scopus 로고
    • Dvorak, D.L., Editor (2009). Nasa study on flight software complexity. Available at http://oceexternal.nasa.gov/OCE_LIB/pdf/1021608main_FSWC_Final_Report.pdf. Last retrieved on November 15, 2009.
    • (2009) Nasa Study on Flight Software Complexity
    • Dvorak, D.L.1
  • 91
    • 85134906601 scopus 로고    scopus 로고
    • Embry-Riddle Aeronautical University (Last retrieved on November 15, 2009). FAA National Wildlife Strike Database. Available at http://wildlife.pr.erau.edu/database/mapping_us_select.php.
    • (2009) FAA National Wildlife Strike Database
  • 93
    • 33644512478 scopus 로고    scopus 로고
    • FAA (Federal Aviation Administration) (2000). FAA System Safety Handbook. Available at http://www.faa.gov/library/manuals/aviation/risk_management/ss_handbook/. Last retrieved on November 15, 2009.
    • (2000) FAA System Safety Handbook
  • 94
    • 84945120633 scopus 로고    scopus 로고
    • Order 8110.4C, U.S. Deparment of Transportation
    • FAA (Federal Aviation Administration) (2007). Type Certification. Order 8110.4C, U.S. Deparment of Transportation.
    • (2007) Type Certification
  • 95
    • 85134911797 scopus 로고    scopus 로고
    • FAA (Federal Aviation Administration) (Last retrieved on November 15, 2009). Airport Wildlife Hazard Mitigation Home Page. Available at http://wildlife-mitigation.tc.faa.gov/public_html/index.html.
    • (2009) Airport Wildlife Hazard Mitigation Home Page
  • 99
    • 22544445562 scopus 로고    scopus 로고
    • Understanding conflict in geographically distributed teams: The moderating effects of shared identity, shared context, and spontaneous communication
    • Hinds, P.J. and M. Mortensen (2005). Understanding conflict in geographically distributed teams: The moderating effects of shared identity, shared context, and spontaneous communication. Organization Science, 16(3), 290–307.
    • (2005) Organization Science , vol.16 , Issue.3 , pp. 290-307
    • Hinds, P.J.1    Mortensen, M.2
  • 100
    • 77954748213 scopus 로고    scopus 로고
    • INCOSE (Last retrieved on November 15, 2009). Requirements Management Tools Survey. Available at http://www.incose.org/ProductsPubs/Products/rmsurvey.aspx.
    • (2009) Requirements Management Tools Survey
  • 101
    • 85134899778 scopus 로고    scopus 로고
    • Information Technology—Software Process Assessment
    • ISO/IEC 15504 (1998). ISO/IEC 15504 : Information Technology—Software Process Assessment—part 7: Guide for Use in Process Improvement.
    • (1998) Guide for Use in Process Improvement
  • 104
    • 0022581573 scopus 로고
    • An experimental evaluation of the assumption of independence in multiversion programming
    • Knight, J.C. and N.G. Leveson (1986). An experimental evaluation of the assumption of independence in multiversion programming. IEEE Transactions on Software Engineering, 12(1), 96–109.
    • (1986) IEEE Transactions on Software Engineering , vol.12 , Issue.1 , pp. 96-109
    • Knight, J.C.1    Leveson, N.G.2
  • 107
    • 0030709925 scopus 로고    scopus 로고
    • An analysis of the Ariane 5 flight 501 failure—a system engineering perspective
    • Washington, D.C.: IEEE Computer Society
    • Lann, G.L. (1997). An analysis of the Ariane 5 flight 501 failure—a system engineering perspective. In Proc. IEEE International Conference and Workshop on Engineering of Computer-Based Systems, pp. 339–346. Washington, D.C.: IEEE Computer Society.
    • (1997) Proc. IEEE International Conference and Workshop on Engineering of Computer-Based Systems , pp. 339-346
    • Lann, G.L.1
  • 108
    • 84945713135 scopus 로고
    • Applying “design by contract
    • Meyer, B. (1992). Applying “design by contract.” Computer 25, 40–51.
    • (1992) Computer , vol.25 , pp. 40-51
    • Meyer, B.1
  • 110
    • 77955443913 scopus 로고    scopus 로고
    • Miller, A. (2008). Distributed Agile Development at Microsoft Patterns & Practices. Available at http://download.microsoft.com/download/4/4/a/44a2cebd-63fb-4379-898d-9cf24822c6cc/distributed_agile_development_at_microsoft_patterns_and_practices.pdf. Last retrieved on November 15, 2009.
    • (2008) Distributed Agile Development at Microsoft Patterns & Practices
    • Miller, A.1
  • 111
    • 85134989939 scopus 로고    scopus 로고
    • A380 hit by new production problems
    • MRY/Reuters (2006). A380 hit by new production problems. Spiegel Online International . Last retrieved on November 15, 2009.
    • (2006) Spiegel Online International
  • 114
    • 0003980056 scopus 로고    scopus 로고
    • Technical Report NASA/SP-2007-6105, Rev1, NASA
    • NASA (2007). NASA Systems Engineering Handbook. Technical Report NASA/SP-2007-6105, Rev1, NASA.
    • (2007) NASA Systems Engineering Handbook
  • 115
    • 85134910965 scopus 로고    scopus 로고
    • NEi Software Inc. (Last retrieved on November 15, 2009). NEi Software Automotive Case Study. Available at http://www.nenastran.com/newnoran/chPDF/CASE_Chassis_Design.pdf.
    • (2009) Nei Software Automotive Case Study
  • 117
    • 33749654993 scopus 로고    scopus 로고
    • Washington, DC: Stationery Office Books
    • Office of Government Commerce (2005). Managing Successful Projects with PRINCE2 (5th revised ed.). Washington, DC: Stationery Office Books.
    • (2005) Managing Successful Projects with PRINCE2
  • 118
    • 0003783281 scopus 로고
    • Normal Accidents: Living with High-Risk Technologies
    • Updated by Princeton, NJ: Princeton University Press
    • Perrow, C. (1984). Normal Accidents: Living with High-Risk Technologies. Basic Books. Updated by Princeton, NJ: Princeton University Press, 1999.
    • (1984) Basic Books
    • Perrow, C.1
  • 120
    • 58049139009 scopus 로고    scopus 로고
    • Newtown Square, PA: Project Management Institute
    • Project Management Institute (2004). A Guide to the Project Management Body of Knowledge (PMBOK ® Guide) (3rd ed.). Newtown Square, PA: Project Management Institute.
    • (2004) A Guide to the Project Management Body of Knowledge
  • 121
    • 1842592072 scopus 로고    scopus 로고
    • Common cause failure data collection and analysis for safetyrelated components of TRIGA SSR-14MW Pitesti, Romania
    • Radu, G. and D. Mladin (2003). Common cause failure data collection and analysis for safetyrelated components of TRIGA SSR-14MW Pitesti, Romania. In Proc. International Conference Nuclear Energy for New Europe 2003.
    • (2003) Proc. International Conference Nuclear Energy for New Europe 2003
    • Radu, G.1    Mladin, D.2
  • 122
    • 0004026606 scopus 로고    scopus 로고
    • Paris, France: European Space Agency
    • Report by the Inquiry Board (1996). Ariane 5 Flight 501 Failure. Paris, France: European Space Agency.
    • (1996) Ariane 5 Flight 501 Failure
  • 124
    • 0002514396 scopus 로고
    • Managing the development of large software systems
    • IEEE Computer Society. Reprinted in Proc. 9th International Conference on Software Engineering, Toronto, Ontario, Canada: ACM Press, 1989, pp. 328–338
    • Royce, W.W. (1970). Managing the development of large software systems. In Proc. Western Electronic Show and Convention (WESCON 1970), pp. 1–9. IEEE Computer Society. Reprinted in Proc. 9th International Conference on Software Engineering, Toronto, Ontario, Canada: ACM Press, 1989, pp. 328–338.
    • (1970) Proc. Western Electronic Show and Convention (WESCON 1970) , pp. 1-9
    • Royce, W.W.1
  • 125
    • 0011964572 scopus 로고    scopus 로고
    • Certification Considerations for Highly-Integrated or Complex Aircraft Systems
    • Warrendale, PA: Society of Automotive Engineers
    • SAE (1996a). Certification Considerations for Highly-Integrated or Complex Aircraft Systems. Technical Report ARP4754. Warrendale, PA: Society of Automotive Engineers.
    • (1996) Technical Report ARP4754
  • 126
    • 0013177364 scopus 로고    scopus 로고
    • Guidelines and Methods for Conducting the Safety Assessment Process on Civil Airborne Systems and Equipment
    • Warrendale, PA: Society of Automotive Engineers
    • SAE (1996b). Guidelines and Methods for Conducting the Safety Assessment Process on Civil Airborne Systems and Equipment. Technical Report ARP4761. Warrendale, PA: Society of Automotive Engineers.
    • (1996) Technical Report ARP4761
  • 128
    • 85134896142 scopus 로고    scopus 로고
    • Software Engineering
    • University of Southern California (1994), Los Angeles, CA: University of Southern California
    • Sommerville, I. (2007). Software Engineering (8th ed.). Reading, MA: Addison-Wesley. University of Southern California (1994). USC COCOMO Reference Manual. Los Angeles, CA: University of Southern California.
    • (2007) USC COCOMO Reference Manual
    • Sommerville, I.1
  • 129
    • 85134973235 scopus 로고    scopus 로고
    • University of Southern California (2000). USC COCOMO II 2000 Software Reference Manual. Available at http://csse.usc.edu/csse/research/COCOMOII/cocomo2000.0/CII_manual2000.0.pdf. Last retrieved on November 15, 2009.
    • (2000) USC COCOMO II 2000 Software Reference Manual
  • 131
    • 85134924791 scopus 로고    scopus 로고
    • Various Authors (Last retrieved on November 15, 2009a). List of GUI Testing Tools. Available at http://en.wikipedia.org/wiki/List_of_GUI_testing_tools.
    • (2009) List of GUI Testing Tools
  • 132
    • 77957738643 scopus 로고    scopus 로고
    • Various Authors (Last retrieved on November 15, 2009b). Revision Control. Available at http://en.wikipedia.org/wiki/Revision_control.
    • (2009) Revision Control
  • 136
    • 85134897255 scopus 로고    scopus 로고
    • Accellera (Last retrieved on November 15, 2009). Accellera. http://www.accellera.org.
    • (2009) Accellera
  • 141
    • 17944367389 scopus 로고    scopus 로고
    • A brief history of process algebra
    • Baeten, J.C.M. (2005). A brief history of process algebra. Theoretical Computer Science 335(2-3), 131–146.
    • (2005) Theoretical Computer Science , vol.335 , Issue.2-3 , pp. 131-146
    • Baeten, J.C.M.1
  • 143
    • 35048871556 scopus 로고    scopus 로고
    • SLAM and Static Driver Verifier: Technology transfer of formal methods inside microsoft
    • Berlin: Springer
    • Ball, T., B. Cook, V. Levin, and S.K. Rajamani (2004). SLAM and Static Driver Verifier: technology transfer of formal methods inside microsoft. In E.A. Boiten, J. Derrick, and G. Smith (Eds.), Proc. 4th International Conference on Integrated Formal Methods (IFM 2004), Volume 2999 of LNCS, pp. 1–20. Berlin: Springer.
    • (2004) Proc. 4Th International Conference on Integrated Formal Methods (IFM 2004) , vol.2999 , pp. 1-20
    • Ball, T.1    Cook, B.2    Levin, V.3    Rajamani, S.K.4
  • 146
    • 0042023007 scopus 로고
    • Formal methods: Use and relevance for the development of safety-critical systems
    • Barroca, L.M. and J.A. McDermid (1992). Formal methods: Use and relevance for the development of safety-critical systems. Computer Journal 35(6), 579–599.
    • (1992) Computer Journal , vol.35 , Issue.6 , pp. 579-599
    • Barroca, L.M.1    McDermid, J.A.2
  • 149
    • 0021291978 scopus 로고
    • Process algebra for synchronous communication
    • Bergstra, J. and J. Klop (1984). Process algebra for synchronous communication. Information and Control 60(1-3), 109–137.
    • (1984) Information and Control , vol.60 , Issue.1-3 , pp. 109-137
    • Bergstra, J.1    Klop, J.2
  • 150
    • 84937570074 scopus 로고    scopus 로고
    • Combination of fault tree analysis and model checking for safety assessment of complex system
    • Berlin: Springer
    • Bieber, P., C. Castel, and C. Seguin (2002). Combination of fault tree analysis and model checking for safety assessment of complex system. In F. Grandoni and P. Thèvenod-Fosse (Eds.), Proc. 4th European Dependable Computing Conference (EDCC-4), Volume 2485 of LNCS, pp. 19–31. Berlin: Springer.
    • (2002) Proc. 4th European Dependable Computing Conference (EDCC-4) , vol.2485 , pp. 19-31
    • Bieber, P.1    Castel, C.2    Seguin, C.3
  • 152
    • 0029346301 scopus 로고
    • Seven more myths of formal methods
    • Bowen, J.P. and M.G. Hinchey (1995). Seven more myths of formal methods. IEEE Software 12(4), 34–41.
    • (1995) IEEE Software , vol.12 , Issue.4 , pp. 34-41
    • Bowen, J.P.1    Hinchey, M.G.2
  • 153
    • 0000175192 scopus 로고
    • Safety-critical systems, formal methods and standards
    • Bowen, J.P. and V. Stavridou (1992). Safety-critical systems, formal methods and standards. BCS/IEE Software Engineering Journal 8(4), 189–209.
    • (1992) BCS/IEE Software Engineering Journal , vol.8 , Issue.4 , pp. 189-209
    • Bowen, J.P.1    Stavridou, V.2
  • 155
    • 33750993028 scopus 로고    scopus 로고
    • Integrating fault tree analysis with event ordering information
    • Leiden, The Netherlands: Balkema Publisher
    • Bozzano, M. and A. Villafiorita (2003). Integrating fault tree analysis with event ordering information. In Proc. European Safety and Reliability Conference (ESREL 2003), pp. 247–254. Leiden, The Netherlands: Balkema Publisher.
    • (2003) Proc. European Safety and Reliability Conference (ESREL 2003) , pp. 247-254
    • Bozzano, M.1    Villafiorita, A.2
  • 157
    • 20044368093 scopus 로고    scopus 로고
    • ESACS: An integrated methodology for design and safety analysis of complex systems
    • Leiden, The Netherlands: Balkema Publisher
    • Bozzano, M., A. Villafiorita, and O. Åkerlund et al. (2003). ESACS: An integrated methodology for design and safety analysis of complex systems. In Proc. European Safety and Reliability Conference (ESREL 2003), pp. 237–245. Leiden, The Netherlands: Balkema Publisher.
    • (2003) Proc. European Safety and Reliability Conference (ESREL 2003) , pp. 237-245
    • Bozzano, M.1    Villafiorita, A.2    Åkerlund, O.3
  • 158
    • 0026913667 scopus 로고
    • Symbolic boolean manipulation with ordered binary decision diagrams
    • Bryant, R.E. (1992). Symbolic boolean manipulation with ordered binary decision diagrams. ACM Computing Surveys 24(3), 293–318.
    • (1992) ACM Computing Surveys , vol.24 , Issue.3 , pp. 293-318
    • Bryant, R.E.1
  • 164
    • 84937557946 scopus 로고    scopus 로고
    • NuSMV2: An opensource tool for symbolic model checking
    • E. Brinksma and K. Larsen (Eds.), Berlin: Springer
    • Cimatti, A., E.M. Clarke, and E. Giunchiglia et al. (2002). NuSMV2: An opensource tool for symbolic model checking. In E. Brinksma and K. Larsen (Eds.), Proc. 14th International Conference on Computer Aided Verification (CAV’02), Volume 2404 of LNCS, pp. 359–364. Berlin: Springer.
    • (2002) Proc. 14th International Conference on Computer Aided Verification , vol.2404 , pp. 359-364
    • Cimatti, A.1    Clarke, E.M.2    Giunchiglia, E.3
  • 165
    • 0002367651 scopus 로고
    • Synthesis of synchronization skeletons for branching time temporal logic
    • D. Kozen (Ed.), Berlin: Springer
    • Clarke, E.M. and E.A. Emerson (1981). Synthesis of synchronization skeletons for branching time temporal logic. In D. Kozen (Ed.), Proc. Workshop on Logic of Programs, Volume 131 of LNCS, pp. 52–71. Berlin: Springer.
    • (1981) Proc. Workshop on Logic of Programs , vol.131 , pp. 52-71
    • Clarke, E.M.1    Emerson, E.A.2
  • 166
    • 0022706656 scopus 로고
    • Automatic verification of finite-state concurrent systems using temporal logic specifications
    • Clarke, E.M., E.A. Emerson, and A. Sistla (1986). Automatic verification of finite-state concurrent systems using temporal logic specifications. ACM TOPLAS 8(2), 244–263.
    • (1986) ACM TOPLAS , vol.8 , Issue.2 , pp. 244-263
    • Clarke, E.M.1    Emerson, E.A.2    Sistla, A.3
  • 167
    • 84957376398 scopus 로고    scopus 로고
    • Verifying the SRT division algorithm using theorem proving techniques
    • In R. Alur and T.A. Henzinger (Eds.), Berlin: Springer
    • Clarke, E.M., S.M. German, and X. Zhao (1996). Verifying the SRT division algorithm using theorem proving techniques. In R. Alur and T.A. Henzinger (Eds.), Proc. 8th International Conference on Computer Aided Verification(CAV’96), Volume 1102 of LNCS, pp. 111–122. Berlin: Springer.
    • (1996) Proc. 8th International Conference on Computer Aided Verification , vol.1102 , pp. 111-122
    • Clarke, E.M.1    German, S.M.2    Zhao, X.3
  • 169
    • 4243189286 scopus 로고    scopus 로고
    • Counterexample-guided abstraction refinement for symbolic model checking
    • Clarke, E.M., O. Grumberg, S. Jha, Y. Lua, and H. Veith (2003). Counterexample-guided abstraction refinement for symbolic model checking. Journal of the ACM 50(5), 752–794.
    • (2003) Journal of the ACM , vol.50 , Issue.5 , pp. 752-794
    • Clarke, E.M.1    Grumberg, O.2    Jha, S.3    Lua, Y.4    Veith, H.5
  • 171
    • 0000289556 scopus 로고    scopus 로고
    • Formal methods: State of the art and future directions
    • Clarke, E.M. and J.M. Wing (1996). Formal methods: State of the art and future directions. ACM Computing Surveys 28, 626–643.
    • (1996) ACM Computing Surveys , vol.28 , pp. 626-643
    • Clarke, E.M.1    Wing, J.M.2
  • 172
    • 38149012481 scopus 로고    scopus 로고
    • Coq (Last retrieved on November 15, 2009). The Coq proof assistant. http://coq.inria.fr.
    • (2009) The Coq Proof Assistant
  • 174
    • 0010118464 scopus 로고
    • Implementing safety critical systems: The VIPER microprocessor
    • Dordrecht, The Netherlands: Kluwer Academic
    • Cullyer, W. (1988). Implementing safety critical systems: The VIPER microprocessor. In Proc. VLSI Specification, Verification and Synthesis, pp. 1–26. Dordrecht, The Netherlands: Kluwer Academic.
    • (1988) Proc. VLSI Specification, Verification and Synthesis , pp. 1-26
    • Cullyer, W.1
  • 176
    • 0029488677 scopus 로고
    • Two examples of verification of multirate timed automata with KRONOS
    • Washington, D.C.: IEEE Computer Society
    • Daws, C. and S. Yovine (1995). Two examples of verification of multirate timed automata with KRONOS. In Proc. 16th IEEE Real-Time Systems Symposium, pp. 66–75. Washington, D.C.: IEEE Computer Society.
    • (1995) Proc. 16th IEEE Real-Time Systems Symposium , pp. 66-75
    • Daws, C.1    Yovine, S.2
  • 177
    • 0036301137 scopus 로고    scopus 로고
    • Formal verification of human-automation interaction
    • Degani, A. and M. Heymann (2002). Formal verification of human-automation interaction. Human Factors 44(1), 28–43.
    • (2002) Human Factors , vol.44 , Issue.1 , pp. 28-43
    • Degani, A.1    Heymann, M.2
  • 181
    • 0026925395 scopus 로고
    • Dynamic fault-tree models for fault-tolerant computer systems
    • Dugan, J., S. Bavuso, and M. Boyd (1992). Dynamic fault-tree models for fault-tolerant computer systems. IEEE Transactions on Reliability 41(3), 363–77.
    • (1992) IEEE Transactions on Reliability , vol.41 , Issue.3 , pp. 363-377
    • Dugan, J.1    Bavuso, S.2    Boyd, M.3
  • 182
    • 43349099019 scopus 로고    scopus 로고
    • E (Last retrieved on November 15, 2009). The E Equational Theorem Prover. http://www4.informatik.tu-muenchen.de/schulz/WORK/eprover.html.
    • (2009) The E Equational Theorem Prover
  • 184
    • 0001449325 scopus 로고
    • Temporal and modal logic
    • In J. van Leeuwen (Ed.), Amsterdam: Elsevier Science
    • Emerson, E.A. (1990). Temporal and modal logic. In J. van Leeuwen (Ed.), Handbook of Theoretical Computer Science, Volume B, pp. 995–1072. Amsterdam: Elsevier Science.
    • (1990) Handbook of Theoretical Computer Science , vol.B , pp. 995-1072
    • Emerson, E.A.1
  • 185
    • 85134972761 scopus 로고    scopus 로고
    • ESACS (Last retrieved on November 15, 2009). The ESACS Project. http://www.esacs.org.
    • (2009) The ESACS Project
  • 186
    • 85134897822 scopus 로고    scopus 로고
    • FSAP (Last retrieved on November 15, 2009). The FSAP/NuSMV-SA platform. https://es.fbk.eu/tools/FSAP.
    • (2009) The Fsap/Nusmv-Sa Platform
  • 189
    • 82055171234 scopus 로고
    • An experience with theLOTOSformal description technique on the flight warning computer of the Airbus A330/340 aircrafts
    • Berlin: Springer
    • Garavel, H. and R. Hautbois (1993). An experience with the LOTOS formal description technique on the flight warning computer of the Airbus A330/340 aircrafts. In 1st AMAST International Workshop on Real-Time Systems. Berlin: Springer.
    • (1993) In 1st amastinternational Workshop on Real-Time Systems
    • Garavel, H.1    Hautbois, R.2
  • 194
    • 0003714504 scopus 로고
    • Springer. Written with S.J. Garland, K.D. Jones, A. Modet, and J.M. Wing. New York: Springer- Verlag
    • Guttag, J.V. and J.J. Horning (1993). Larch: Languages and Tools for Formal Specification. Springer. Written with S.J. Garland, K.D. Jones, A. Modet, and J.M. Wing. New York: Springer- Verlag.
    • (1993) Larch: Languages and Tools for Formal Specification
    • Guttag, J.V.1    Horning, J.J.2
  • 195
    • 0025489197 scopus 로고
    • Seven myths of formal methods
    • Hall, A. (1990). Seven myths of formal methods. IEEE Software 7(5), 11–19.
    • (1990) IEEE Software , vol.7 , Issue.5 , pp. 11-19
    • Hall, A.1
  • 196
    • 0030106817 scopus 로고    scopus 로고
    • Using formal methods to develop an ATC information system
    • Hall, A. (1996). Using formal methods to develop an ATC information system. IEEE Software 13(2), 66–76.
    • (1996) IEEE Software , vol.13 , Issue.2 , pp. 66-76
    • Hall, A.1
  • 197
    • 0023365727 scopus 로고
    • Statecharts: A visual formalism for complex systems
    • Harel, D. (1987). Statecharts: A visual formalism for complex systems. Science of Computer Programming 8, 231–274.
    • (1987) Science of Computer Programming , vol.8 , pp. 231-274
    • Harel, D.1
  • 198
    • 4544221419 scopus 로고    scopus 로고
    • Completeness and consistency in hierarchical state-based requirements
    • Heimdahl, M. and N.G. Leveson (1996). Completeness and consistency in hierarchical state-based requirements. IEEE Transactions on Software Engineering 22(6), 363–377.
    • (1996) IEEE Transactions on Software Engineering , vol.22 , Issue.6 , pp. 363-377
    • Heimdahl, M.1    Leveson, N.G.2
  • 199
    • 26444560470 scopus 로고    scopus 로고
    • Incremental and complete bounded model checking for full PLTL
    • In K. Etessami and S.K. Rajamani (Eds.), Berlin: Springer
    • Heljanko, K., T. Junttila, and T. Latvala (2005). Incremental and complete bounded model checking for full PLTL. In K. Etessami and S.K. Rajamani (Eds.), Proc. 17th International Conference on Computer Aided Verification(CAV’05), Volume 3576 of LNCS, pp. 98–111. Berlin: Springer.
    • (2005) Proc. 17Th International Conference on Computer Aided Verification , vol.3576 , pp. 98-111
    • Heljanko, K.1    Junttila, T.2    Latvala, T.3
  • 201
    • 84945708698 scopus 로고
    • An axiomatic basis of computer programming
    • Hoare, C.A.R. (1969). An axiomatic basis of computer programming. Communications of the ACM 12(10), 576–580.
    • (1969) Communications of the ACM , vol.12 , Issue.10 , pp. 576-580
    • Hoare, C.A.R.1
  • 204
    • 84956965964 scopus 로고
    • CICS project report: Experiences and results from the use of Z in IBM
    • S. Prehn and W. Toetenel (Eds.), Berlin: Springer
    • Houston, I. and S. King (1991). CICS project report: Experiences and results from the use of Z in IBM. In S. Prehn and W. Toetenel (Eds.), Proc. 4th International Symposium of VDM Europe (VDM’91), Volume 552 of LNCS, pp. 588–596. Berlin: Springer.
    • (1991) Proc. 4th International Symposium of VDM Europe (VDM’91) , vol.552 , pp. 588-596
    • Houston, I.1    King, S.2
  • 205
    • 85134968011 scopus 로고    scopus 로고
    • IEEE 1850 (Last retrieved on November 15, 2009). IEEE 1850. http://www.eda.org/ieee-1850.
    • (2009) IEEE 1850
  • 206
    • 85134908330 scopus 로고    scopus 로고
    • ISAAC (Last retrieved on November 15, 2009). The ISAAC Project. http://www.cert.fr/isaac.
    • (2009) The ISAAC Project
  • 210
    • 33646134101 scopus 로고    scopus 로고
    • Model-based safety analysis of simulink models using SCADE design verifier
    • In R. Winther, B. Gran, and G. Dahll (Eds.), Berlin: Springer
    • Joshi, A. and M. Heimdahl (2005). Model-based safety analysis of simulink models using SCADE design verifier. In R. Winther, B. Gran, and G. Dahll (Eds.), Proc. 24th International Conference on Computer Safety, Reliability and Security (SAFECOMP 2005), Volume 3688 of LNCS, pp. 122–135. Berlin: Springer.
    • (2005) Proc. 24th International Conference on Computer Safety, Reliability and Security , vol.3688 , pp. 122-135
    • Joshi, A.1    Heimdahl, M.2
  • 212
    • 70350219116 scopus 로고    scopus 로고
    • Replacing testing with formal verification in Intel R _ CoreTM i7 processor execution engine validation
    • In A. Bouajjani and O. Maler (Eds.), Berlin: Springer
    • Kaivola, R., R. Ghughal, and N. Narasimhan et al. (2009). Replacing testing with formal verification in Intel R _ CoreTM i7 processor execution engine validation. In A. Bouajjani and O. Maler (Eds.), Proc. 21st International Conference on Computer Aided Verification (CAV’09), Volume 5643 of LNCS, pp. 414–429. Berlin: Springer.
    • (2009) Proc. 21st International Conference on Computer Aided Verification (CAV’09) , vol.5643 , pp. 414-429
    • Kaivola, R.1    Ghughal, R.2    Narasimhan, N.3
  • 216
    • 38149060047 scopus 로고    scopus 로고
    • Human error analysis based on a semantically defined cognitive pilot model
    • F. Saglietti and N. Oster (Eds.), Berlin: Springer
    • Lüdtke, A. and L. Pfeiffer (2007). Human error analysis based on a semantically defined cognitive pilot model. In F. Saglietti and N. Oster (Eds.), Proc. 26th International Conference on Computer Safety, Reliability and Security (SAFECOMP 2007), Number 4680 in LNCS, pp. 134–147. Berlin: Springer.
    • (2007) Proc. 26th International Conference on Computer Safety, Reliability and Security , vol.4680 , pp. 134-147
    • Lüdtke, A.1    Pfeiffer, L.2
  • 219
    • 0003581143 scopus 로고
    • Dordrecht, The Netherlands: Kluwer Academic
    • McMillan, K.L. (1993). Symbolic Model Checking. Dordrecht, The Netherlands: Kluwer Academic.
    • (1993) Symbolic Model Checking
    • McMillan, K.L.1
  • 220
    • 0029214615 scopus 로고
    • Formal verification of the AAMP5 microprocessor: A case study in the industrial use of formal methods
    • Washington, D.C.: IEEE Computer Society
    • Miller, S.P. and M. Srivas (1995). Formal verification of the AAMP5 microprocessor: A case study in the industrial use of formal methods. In Proc. Workshop on Industrial-Strength Formal Specification Techniques (WIFT’95), pp. 2–16. Washington, D.C.: IEEE Computer Society.
    • (1995) Proc. Workshop on Industrial-Strength Formal Specification Techniques (WIFT’95) , pp. 2-16
    • Miller, S.P.1    Srivas, M.2
  • 223
  • 225
    • 85034570506 scopus 로고
    • Reasoning in interval temporal logic
    • Berlin: Springer
    • Moszkowski, B.C. and Z. Manna (1983). Reasoning in interval temporal logic. In Proc. Workshop on Logic of Programs, Volume 164 of LNCS, pp. 371–382. Berlin: Springer.
    • (1983) Proc. Workshop on Logic of Programs , vol.164 , pp. 371-382
    • Moszkowski, B.C.1    Manna, Z.2
  • 228
    • 85134954025 scopus 로고    scopus 로고
    • NuPRL (Last retrieved on November 15, 2009). The PRL Automated Reasoning Project.http://www.cs.cornell.edu/Info/Projects/NuPRL.
    • (2009) The PRL Automated Reasoning Project
  • 230
    • 85134905452 scopus 로고    scopus 로고
    • Otter (Last retrieved on November 15, 2009). The Otter Theorem Prover. http://www.cs.unm.edu/mccune/otter.
    • (2009) The Otter Theorem Prover
  • 233
    • 85134966387 scopus 로고
    • Communication with Automata
    • Fort Belvoir, VA
    • Petri, C. (1966). Communication with Automata. DTIC Research Report AD0630125. Defense Technical Information Center, Fort Belvoir, VA.
    • (1966) Defense Technical Information Center
    • Petri, C.1
  • 235
    • 49149133038 scopus 로고
    • A temporal logic of concurrent programs
    • Pnueli, A. (1981). A temporal logic of concurrent programs. Theoretical Computer Science 13, 45–60.
    • (1981) Theoretical Computer Science , vol.13 , pp. 45-60
    • Pnueli, A.1
  • 236
    • 25144498654 scopus 로고    scopus 로고
    • A survey of recent advances in SAT-based formal verification
    • Prasad, M.R., A. Biere, and A. Gupta (2005). A survey of recent advances in SAT-based formal verification. Software Tools for Technology Transfer 7(2), 156–173.
    • (2005) Software Tools for Technology Transfer , vol.7 , Issue.2 , pp. 156-173
    • Prasad, M.R.1    Biere, A.2    Gupta, A.3
  • 238
    • 85134907212 scopus 로고    scopus 로고
    • Prover9 (Last retrieved on November 15, 2009). The Prover9 Theorem Prover. http://www.cs.unm.edu/mccune/prover9.
    • (2009) The Prover9 Theorem Prover
  • 239
    • 85134991925 scopus 로고    scopus 로고
    • PSL (Last retrieved on November 15, 2009). The PSL/Sugar Consortium. http://www.pslsugar.org.
    • (2009) The Psl/Sugar Consortium
  • 243
    • 0027289814 scopus 로고
    • New algorithms for fault trees analysis
    • Rauzy, A. (1993). New algorithms for fault trees analysis. Reliability Engineering and System Safety 40(3), 203–211.
    • (1993) Reliability Engineering and System Safety , vol.40 , Issue.3 , pp. 203-211
    • Rauzy, A.1
  • 248
    • 0036466927 scopus 로고    scopus 로고
    • Using model checking to help discover mode confusions and other automation surprises
    • Rushby, J. (2002). Using model checking to help discover mode confusions and other automation surprises. Reliability Engineering and System Safety 75(2), 167–177.
    • (2002) Reliability Engineering and System Safety , vol.75 , Issue.2 , pp. 167-177
    • Rushby, J.1
  • 249
    • 0043092223 scopus 로고    scopus 로고
    • High level formal verification of next-generation microprocessors
    • New York: ACM
    • Schubert, T. (2003). High level formal verification of next-generation microprocessors. In Proc. 40th Design Automation Conference (DAC’03), pp. 1–6. New York: ACM.
    • (2003) Proc. 40th Design Automation Conference (DAC’03) , pp. 1-6
    • Schubert, T.1
  • 250
    • 85134973689 scopus 로고    scopus 로고
    • Setheo (Last retrieved on November 15, 2009). The Theorem Prover Setheo. http://www.tcs.informatik.uni-muenchen.de/letz/TU/setheo.
    • (2009) The Theorem Prover Setheo
  • 252
    • 85134996212 scopus 로고    scopus 로고
    • SLAM (Last retrieved on November 15, 2009). The SLAM Project. http://research.microsoft.com/en-us/projects/slam.
    • (2009) The SLAM Project
  • 256
    • 85134977968 scopus 로고    scopus 로고
    • STeP (Last retrieved on November 15, 2009). The Stanford Temporal Prover. http://wwwstep.stanford.edu.
    • (2009) The Stanford Temporal Prover
  • 259
    • 0035446960 scopus 로고    scopus 로고
    • Software engineering with formal methods: The development of a storm surge barrier control system revisiting seven myths of formal methods
    • Tretmans, J., K. Wijbrans, and M. Chaudron (2001). Software engineering with formal methods: The development of a storm surge barrier control system revisiting seven myths of formal methods. Formal Methods in System Design 19(2), 195–215.
    • (2001) Formal Methods in System Design , vol.19 , Issue.2 , pp. 195-215
    • Tretmans, J.1    Wijbrans, K.2    Chaudron, M.3
  • 260
    • 85134913953 scopus 로고    scopus 로고
    • UPPAAL (Last retrieved on November 15, 2009). UPPAAL. http://www.uppaal.com.
    • (2009) UPPAAL
  • 261
    • 85134954578 scopus 로고    scopus 로고
    • Vampire (Last retrieved on November 15, 2009). Vampire. http://www.voronkov.com/vampire.cgi.
    • (2009) Vampire
  • 263
    • 0022987223 scopus 로고
    • An automata-theoretic approach to automatic program verification
    • Washington, D.C.: IEEE Computer Society
    • Vardi, M.Y. and P. Wolper (1986). An automata-theoretic approach to automatic program verification. In Proc. Symposium on Logic in Computer Science (LICS ’86), pp. 332–344. Washington, D.C.: IEEE Computer Society.
    • (1986) Proc. Symposium on Logic in Computer Science (LICS ’86) , pp. 332-344
    • Vardi, M.Y.1    Wolper, P.2
  • 269
    • 38349042923 scopus 로고    scopus 로고
    • AIA, GAMA, and FAA Aircraft Certification Service (2004). The FAA and Industry Guide to Product Certification. Available at http://www.faa.gov/aircraft/air_cert/design_approvals/media/CPI_guide_II.pdf. Last retrieved on November 15, 2009.
    • (2004) The FAA and Industry Guide to Product Certification
  • 270
    • 85134935368 scopus 로고    scopus 로고
    • Clarification of Structure Coverage Analyses of Data Coupling and Control Coupling
    • Certification Authorities Software Team (2004). Clarification of Structure Coverage Analyses of Data Coupling and Control Coupling. Position Paper CAST-19, Federal Aviation Administration. Last retrieved on November 15, 2009.
    • (2004) Position Paper CAST-19, Federal Aviation Administration
  • 272
    • 85134909094 scopus 로고    scopus 로고
    • Department of Defense (Last retrieved on November 15, 2009). Assist. Available at https://assist.daps.dla.mil/online/start/.
    • (2009) Assist.
  • 275
    • 85134968223 scopus 로고    scopus 로고
    • EUROCAE (Last retrieved on November 15, 2009). EUROCAE web site: http://www.eurocae.net.
    • (2009) EUROCAE
  • 276
    • 77955948615 scopus 로고    scopus 로고
    • Technical Document DAP/SSH/091, European Union
    • EUROCONTROL (2006). Safety Case Development Manual. Technical Document DAP/SSH/091, European Union.
    • (2006) Safety Case Development Manual
  • 277
    • 79959383493 scopus 로고    scopus 로고
    • European Cooperation for Space Standardization (Last retrieved on November 15, 2009). European Cooperation for Space Standardization web site. Available at http://www.ecss.nl/.
    • (2009) European Cooperation for Space Standardization
  • 278
    • 85134903634 scopus 로고
    • RTCA/DO-178B, Software Considerations in Airborne Systems and Equipment Certification
    • Federal Aviation Administration (1993). RTCA/DO-178B, Software Considerations in Airborne Systems and Equipment Certification. AC 20-115B, Federal Aviation Administration. Last retrieved on November 15, 2009.
    • (1993) AC 20-115B, Federal Aviation Administration
  • 279
    • 0011998335 scopus 로고    scopus 로고
    • Advisory Circular 25.1309-1A, U.S. Deparment of Transportation
    • Federal Aviation Administration (1998). System Design and Analysis. Advisory Circular 25.1309-1A, U.S. Deparment of Transportation.
    • (1998) System Design and Analysis
  • 280
    • 85134984048 scopus 로고    scopus 로고
    • Design Assurance Guidance for Airborne Electronic Hardware
    • Federal Aviation Administration (2005). RTCA/DO-254, Design Assurance Guidance for Airborne Electronic Hardware. AC 20-152, Federal Aviation Administration. Last retrieved on November 15, 2009.
    • (2005) Federal Aviation Administration
  • 281
    • 85135000823 scopus 로고    scopus 로고
    • Type Certification
    • Federal Aviation Administration (2007). Type Certification. Order 8110.4C, U.S. Deparment of Transportation.
    • (2007) Deparment of Transportation
  • 285
    • 0025492027 scopus 로고
    • Integrating formal methods into the development process
    • Kemmerer, R.A. (1990). Integrating formal methods into the development process. IEEE Software 7(5), 37–50.
    • (1990) IEEE Software , vol.7 , Issue.5 , pp. 37-50
    • Kemmerer, R.A.1
  • 287
    • 85134934728 scopus 로고    scopus 로고
    • Ministry of Defence (Last retrieved on November 15, 2009). UK Defence Standardization website. Available at http://www.dstan.mod.uk/.
    • (2009) UK Defence Standardization Website
  • 288
    • 85134980342 scopus 로고    scopus 로고
    • NASA (Last retrieved on November 15, 2009). Software Requirements Review (SRR) Checklist. Available at http://swassurance.gsfc.nasa.gov/disciplines/quality/checklists/pdf/software_requirements_review.pdf.
    • (2009) Software Requirements Review (SRR) Checklist
  • 289
    • 0032731082 scopus 로고    scopus 로고
    • The potential for a generic approach to certification of safety-critical systems in the transportation sector
    • Papadopoulos, Y. and J.A. McDermid (1999). The potential for a generic approach to certification of safety-critical systems in the transportation sector. Journal of Reliability Engineering and System Safety 63(47–66).
    • (1999) Journal of Reliability Engineering and System Safety , vol.63 , Issue.47-66
    • Papadopoulos, Y.1    McDermid, J.A.2
  • 294
    • 84911352314 scopus 로고    scopus 로고
    • Evolution of the framework’s quagmire
    • Sheard, S.A. (2001). Evolution of the framework’s quagmire. Computer 34(7), 96–98.
    • (2001) Computer , vol.34 , Issue.7 , pp. 96-98
    • Sheard, S.A.1
  • 296
    • 85134929906 scopus 로고    scopus 로고
    • Digital Avionics Handbook—Avionics, Elements, Software, and Functions
    • Spitzer, C.R. (Ed.) (2006). Digital Avionics Handbook—Avionics, Elements, Software, and Functions (2nd ed.). Boca Raton, FL: CRC. U.S. Government (Last retrieved on November 15, 2009). Code of Federal Regulations, Title 14—Aeronautics and Space. Available at http://ecfr.gpoaccess.gov/cgi/t/text/text-idx?c=ecfr&tpl=/ecfrbrowse/Title14/14tab_02.tpl.
    • (2006) Code of Federal Regulations, Title 14—Aeronautics and Space
    • Spitzer, C.R.1
  • 299
    • 38049165554 scopus 로고    scopus 로고
    • A symbolic model checking framework for safety analysis, diagnosis, and synthesis
    • Berlin: Springer
    • Bertoli, P., M. Bozzano, and A. Cimatti (2007). A symbolic model checking framework for safety analysis, diagnosis, and synthesis. In Model Checking and Artificial Intelligence, Volume 4428 of LNCS, pp. 1–18. Berlin: Springer.
    • (2007) Model Checking and Artificial Intelligence , vol.4428 , pp. 1-18
    • Bertoli, P.1    Bozzano, M.2    Cimatti, A.3
  • 305
    • 0026913667 scopus 로고
    • Symbolic Boolean manipulation with ordered binary decision diagrams
    • Bryant, R.E. (1992). Symbolic Boolean manipulation with ordered binary decision diagrams. ACM Computing Surveys 24(3), 293–318.
    • (1992) ACM Computing Surveys , vol.24 , Issue.3 , pp. 293-318
    • Bryant, R.E.1
  • 312
    • 0038517219 scopus 로고    scopus 로고
    • Weak, strong, and strong cyclic planning via symbolic model checking
    • Cimatti, A., M. Pistore, M. Roveri, and P. Traverso (2003b). Weak, strong, and strong cyclic planning via symbolic model checking. Artificial Intelligence 147(1-2), 35–84.
    • (2003) Artificial Intelligence , vol.147 , Issue.1-2 , pp. 35-84
    • Cimatti, A.1    Pistore, M.2    Roveri, M.3    Traverso, P.4
  • 314
    • 0004000699 scopus 로고    scopus 로고
    • CUDD (Last retrieved on November 15, 2009). CUDD: CU Decision Diagram Package. http://vlsi.colorado.edu/fabio/CUDD.
    • (2009) CUDD: CU Decision Diagram Package
  • 315
    • 85134957545 scopus 로고    scopus 로고
    • FBK (Last retrieved on November 15, 2009). Fondazione Bruno Kessler. http://www.fbk.eu.
    • (2009) Fondazione Bruno Kessler
  • 316
    • 85134897822 scopus 로고    scopus 로고
    • FSAP (Last retrieved on November 15, 2009). The FSAP/NuSMV-SA platform. https://es.fbk.eu/tools/FSAP.
    • (2009) The Fsap/Nusmv-Sa Platform
  • 318
    • 85134903122 scopus 로고    scopus 로고
    • LGPL (Last retrieved on November 15, 2009). The GNU Lesser General Public License. http://www.fsf.org/licensing/licenses/lgpl.html.
    • (2009) The GNU Lesser General Public License
  • 319
    • 85134977218 scopus 로고    scopus 로고
    • MBP (Last retrieved on November 15, 2009). The MBP Model Based Planner. http://mbp.fbk.eu.
    • (2009) The MBP Model Based Planner
  • 320
    • 0003581143 scopus 로고
    • Dordrecht, The Netherlands: Kluwer Academic
    • McMillan, K.L. (1993). Symbolic Model Checking. Dordrecht, The Netherlands: Kluwer Academic.
    • (1993) Symbolic Model Checking
    • McMillan, K.L.1
  • 321
    • 85134954867 scopus 로고    scopus 로고
    • MiniSat (Last retrieved on November 15, 2009). The MiniSat Page. http://minisat.se.
    • (2009) The Minisat Page
  • 323
    • 78650384759 scopus 로고    scopus 로고
    • OS (Last retrieved on November 15, 2009). The Open Source Initiative. http://www.opensource.org.
    • (2009) The Open Source Initiative
  • 325
    • 85135000076 scopus 로고    scopus 로고
    • The RAT Requirements Analysis tool
    • RAT (Last retrieved on November 15, 2009). The RAT Requirements Analysis tool. http://rat.fbk.eu.zChaff (Last retrieved on November 15, 2009). ZChaff. http://www.princeton.edu/chaff/zchaff.html.
    • (2009) Zchaff.
  • 332
    • 33750993028 scopus 로고    scopus 로고
    • Integrating fault tree analysis with event ordering information
    • Leiden, The Netherlands: Balkema Publisher
    • Bozzano, M. and A. Villafiorita (2003). Integrating fault tree analysis with event ordering information. In Proc. European Safety and Reliability Conference (ESREL 2003), pp. 247–254. Leiden, The Netherlands: Balkema Publisher.
    • (2003) Proc. European Safety and Reliability Conference (ESREL 2003) , pp. 247-254
    • Bozzano, M.1    Villafiorita, A.2
  • 334
    • 20044368093 scopus 로고    scopus 로고
    • ESACS: An integrated methodology for design and safety analysis of complex systems
    • (b), Leiden, The Netherlands: Balkema Publisher
    • Bozzano, M., A. Villafiorita, O. Åkerlund et al. (2003b). ESACS: An integrated methodology for design and safety analysis of complex systems. In Proc. European Safety and Reliability Conference (ESREL 2003), pp. 237–245. Leiden, The Netherlands: Balkema Publisher.
    • (2003) Proc. European Safety and Reliability Conference (ESREL 2003) , pp. 237-245
    • Bozzano, M.1    Villafiorita, A.2    Kerlund, O.Å.3
  • 335
    • 85134982178 scopus 로고    scopus 로고
    • COMPASS (Last retrieved on November 15, 2009). The COMPASS Project. http://compass.informatik.rwth-aachen.de.
    • (2009) The COMPASS Project
  • 336
    • 0026973232 scopus 로고
    • Implicit and incremental computation of primes and essential primes of Boolean functions
    • IEEE Computer Society
    • Coudert, O. and J.C. Madre (1992). Implicit and incremental computation of primes and essential primes of Boolean functions. In Proc. 29th Design Automation Conference (DAC’92), pp. 36–39. IEEE Computer Society.
    • (1992) Proc. 29Th Design Automation Conference (DAC’92) , pp. 36-39
    • Coudert, O.1    Madre, J.C.2
  • 338
    • 0004000699 scopus 로고    scopus 로고
    • CUDD (Last retrieved on November 15, 2009). CUDD: CU Decision Diagram Package. http://vlsi.colorado.edu/fabio/CUDD.
    • (2009) CUDD: CU Decision Diagram Package
  • 339
    • 85134972761 scopus 로고    scopus 로고
    • ESACS (Last retrieved on November 15, 2009). The ESACS Project. http://www.esacs.org.
    • (2009) The ESACS Project
  • 340
    • 77951996047 scopus 로고    scopus 로고
    • Expat (Last retrieved on November 15, 2009). The Expat XML Parser. http://expat.sourceforge.net.
    • (2009) The Expat XML Parser
  • 341
    • 85134957545 scopus 로고    scopus 로고
    • FBK (Last retrieved on November 15, 2009). Fondazione Bruno Kessler. http://www.fbk.eu.
    • (2009) Fondazione Bruno Kessler
  • 342
    • 85134974379 scopus 로고    scopus 로고
    • FLTK (Last retrieved on November 15, 2009). FLTK: Fast Light Toolkit. http://www.fltk.org.
    • (2009) FLTK: Fast Light Toolkit
  • 343
    • 85134897822 scopus 로고    scopus 로고
    • FSAP (Last retrieved on November 15, 2009). The FSAP/NuSMV-SA Platform. https://es.fbk.eu/tools/FSAP.
    • (2009) The Fsap/Nusmv-Sa Platform
  • 345
    • 85134981056 scopus 로고    scopus 로고
    • FT+ (Last retrieved on November 15, 2009). FaultTree+. http://www.isographsoftware.com/ftpover.htm.
    • (2009) Faulttree
  • 346
    • 85134908330 scopus 로고    scopus 로고
    • ISAAC (Last retrieved on November 15, 2009). The ISAAC Project. http://www.cert.fr/isaac.
    • (2009) The ISAAC Project
  • 347
    • 85134954867 scopus 로고    scopus 로고
    • MiniSat (Last retrieved on November 15, 2009). The MiniSat Page. http://minisat.se.
    • (2009) The Minisat Page
  • 348
    • 85134940879 scopus 로고    scopus 로고
    • MISSA (Last retrieved on November 15, 2009). The MISSA Project. http://www.missafp7.eu.
    • (2009) The MISSA Project
  • 350
    • 85134914958 scopus 로고    scopus 로고
    • OMC-ARE (Last retrieved on November 15, 2009). The OMC-ARE Project. http://es.fbk.eu/projects/esa_omc-are.
    • (2009) The OMC-ARE Project
  • 351
    • 0027289814 scopus 로고
    • New algorithms for fault trees analysis
    • Rauzy, A. (1993). New algorithms for fault trees analysis. Reliability Engineering and System Safety 40(3), 203–211.
    • (1993) Reliability Engineering and System Safety , vol.40 , Issue.3 , pp. 203-211
    • Rauzy, A.1
  • 352
    • 0031276402 scopus 로고    scopus 로고
    • Exact and truncated computations of prime implicants of coherent and non-coherent fault trees within Aralia
    • Rauzy, A. and Y. Dutuit (1997). Exact and truncated computations of prime implicants of coherent and non-coherent fault trees within Aralia. Reliability Engineering and System Safety 58(2), 127–144.
    • (1997) Reliability Engineering and System Safety , vol.58 , Issue.2 , pp. 127-144
    • Rauzy, A.1    Dutuit, Y.2
  • 353
    • 85134928824 scopus 로고    scopus 로고
    • zChaff (Last retrieved on November 15, 2009). zChaff. http://www.princeton.edu/chaff/zchaff.html.
    • (2009) Zchaff
  • 354
    • 85134928097 scopus 로고    scopus 로고
    • FAA (Last retrieved on November 15, 2009a). FAA mission. Available at http://www.faa.gov/about/mission/.
    • (2009) FAA Mission


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.