首页> 外文学位 >Pandora: An approach to analyzing safety-related digital-system failures.
【24h】

Pandora: An approach to analyzing safety-related digital-system failures.

机译:Pandora:一种用于分析与安全相关的数字系统故障的方法。

获取原文
获取原文并翻译 | 示例

摘要

Safety-related systems are those whose failure could result in loss of life, injury, or damage to property. The use of software and programmable electronic systems in safety-related domains, which include aerospace, commercial aviation, medicine, and nuclear power generation, is increasing. This increased reliance on digital systems to control potentially hazardous operations or to alert operators to dangerous conditions creates new failure modes and risks that might lead to accidents, and it poses new system development and safety assurance challenges.; Ensuring that digital systems will operate at least as dependably as the mechanical and analog systems they replace is essential, but achieving this level of dependability in a digital system can be exceptionally difficult. The design faults that plague digital systems are harder to identify and address than the physical faults that precede the bulk of mechanical and analog system failures. These design faults, coupled with the complex new designs that digital systems typically implement, complicate the safety assurance of digital systems. The increased reliance on digital systems to perform safety-related functions and the difficulty of ensuring that they will do so correctly increase the probability of accidents.; Analyzing safety-related failures of digital systems can yield lessons for improving development and assurance practices in order to reduce the risk of future accidents, but the same factors that complicate the safety assurance of these systems also affect failure analysis. Traditional techniques for investigating accidents assume that systems exhibit a common set of failure modes and that each failure mode leaves evidence that can be discovered from the accident scene. Such is not the case for digital systems, and so new techniques are needed to address the unique challenges that digital systems pose.; To address this problem, this dissertation introduces the Pandora approach to failure analysis. Pandora is a systematic but manual approach to analyzing safety-related failures of digital systems in which the analysis is framed around a system's safety case. The safety case documents the complete argument that the system is acceptably safe to operate, and framing failure analysis around the safety case provides important benefits. Investigators applying Pandora to a failure examine the safety case for fallacies; the presence of a fallacy in the safety case suggests the existence of a fault in the system that might have contributed to the failure. Pandora guides investigators through the steps of developing theories of the failure, eliciting evidence, and developing lessons and recommendations that address the problems the investigators identify. While Pandora may be applied to a wide array of system accidents, this dissertation focuses on its application to those involving safety-related digital systems.; Pandora is accompanied by a taxonomy of safety-argument fallacies to assist investigators in applying the process. The taxonomy documents fallacious reasoning that might appear in safety arguments and was developed from separate surveys of fallacies in real-world safety arguments and of fallacies documented in the philosophical literature. It may be used with Pandora or separately to assist in the detection of safety-argument fallacies.; Pandora was applied to a series of commercial-aviation accidents involving a minimum safe altitude warning system, and the safety-argument fallacy taxonomy was evaluated through a controlled study involving twenty computer-science graduate students, engineers, and safety professionals. In the former study, the application of Pandora produced findings comparable to those of the official investigations into the accidents. The latter study, while statistically inconclusive, suggests that the fallacy taxonomy assists the detection of fallacies in safety arguments. While both studies have significant limitations, they show that the Pand
机译:与安全相关的系统是指那些可能导致人员伤亡或财产损失的系统。在与安全相关的领域(包括航空航天,商业航空,医学和核能发电)中,软件和可编程电子系统的使用正在增加。越来越依赖数字系统来控制潜在的危险操作或警告操作员注意危险情况,这会导致新的故障模式和可能导致事故的风险,并给系统开发和安全保证带来新的挑战。确保数字系统至少能够像它们所取代的机械和模拟系统一样可靠地运行,但是,要在数字系统中达到这种水平的可靠性可能会异常困难。与大量机械和模拟系统故障之前的物理故障相比,困扰数字系统的设计故障更难识别和解决。这些设计错误,再加上数字系统通常实施的复杂的新设计,使数字系统的安全保证变得更加复杂。越来越依赖数字系统来执行与安全相关的功能,并且难以确保数字系统能够正确执行此功能,从而增加了发生事故的可能性。分析数字系统与安全相关的故障可以提供教训,以改进开发和保证实践,从而减少未来事故的风险,但是使这些系统的安全保证复杂化的相同因素也影响故障分析。用于调查事故的传统技术假定系统表现出一组常见的故障模式,并且每种故障模式都留下了可以从事故现场中发现的证据。对于数字系统而言并非如此,因此需要新技术来解决数字系统带来的独特挑战。为了解决这个问题,本文将潘多拉模型引入故障分析。 Pandora是一种系统的但人工的方法,用于分析数字系统与安全相关的故障,该分析围绕系统的安全案例进行。安全案例记录了有关系统可以安全运行的完整论点,围绕安全案例进行框架故障分析可提供重要的好处。将潘多拉(Pandora)应用于故障的研究人员检查了安全案例的谬误;安全案例中存在谬论表明系统中可能存在导致故障的故障。潘多拉(Pandora)指导研究人员完成开发故障理论,寻找证据以及开发课程和建议的步骤,以解决研究人员发现的问题。尽管Pandora可能适用于各种各样的系统事故,但本文主要关注其在涉及安全相关数字系统的事故中的应用。潘多拉(Pandora)伴随着安全论点谬论的分类法,以协助调查人员应用该过程。分类法记录了可能会出现在安全论证中的谬论,并且是根据对现实世界中安全论证的谬论和哲学文献中记录的谬论的单独调查得出的。它可以与Pandora一起使用,也可以单独使用以协助检测安全参数谬误。 Pandora被应用于一系列涉及最低安全高度警告系统的商业航空事故,并且通过一项涉及20名计算机科学研究生,工程师和安全专业人员的对照研究,对安全论点谬误分类法进行了评估。在以前的研究中,潘多拉的应用所产生的发现可与官方对事故的调查相媲美。后者的研究虽然在统计上尚无定论,但表明谬误分类法有助于安全论证中的谬误检测。尽管两项研究都有明显的局限性,但它们表明

著录项

  • 作者

    Greenwell, William S.;

  • 作者单位

    University of Virginia.;

  • 授予单位 University of Virginia.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2007
  • 页码 238 p.
  • 总页数 238
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号