Path: utzoo!attcan!utgpu!jarvis.csri.toronto.edu!mailrus!purdue!ames!henry.jpl.nasa.gov!elroy.jpl.nasa.gov!ucla-cs!uci-ics!nancy
From: nancy@ics.uci.edu (Nancy Leveson)
Newsgroups: comp.software-eng
Subject: Re: Software Failure Analysis
Keywords: Software failure analysis, quantization errors, resolution
Message-ID: <1989Sep30.034337.9238@paris.ics.uci.edu>
Date: 30 Sep 89 03:43:37 GMT
References: <10743@dasys1.UUCP> <34348@regenmeister.uucp> <592@halley.UUCP> <290@cs.nps.navy.mil> <27545@shemp.CS.UCLA.EDU>
Sender: news@paris.ics.uci.edu (Network News)
Reply-To: Nancy Leveson 
Organization: University of California, Irvine - Dept of ICS
Lines: 30


Besides the papers that Tim Shimeall mentions on failure analysis, there is
also a set of papers on "software safety" that describe how to apply to
software some of the same types of failure analysis done in engineering.
If you are interested in this, one place to start is:
   Leveson, N.B. "Software Safety: Why, What and How,"  ACM Computing Surveys,
   Vol 18, No. 2, June 1986.
This contains a lot of references.

With respect to the letter by Jia Hong Chen about John Knight and my 
experiment, I have seen only an earlier paper by Peter Bishop in which he
attempted to explain our results as having been a result of "failure masking."
Unfortunately, this does not explain the results, but Peter was hampered by
not having the detailed data from our experiment needed to know this.

For those interested, there will be a paper appearing this spring in IEEE
Transactions on Software Engineering that provides a detailed explanation 
of the faults that led to statistically dependent failures in our original
experiment along with a model that attempts to explain this phenomena.  

There has also been a replication of our experiment -- they got the same 
results as we did.  Analysis of the program failure behavior of the programs 
developed for an n-version programming experiment in which UCLA was one of 
the 4 participating universities showed virtually identical results with 
the Knight and Leveson experiment.

nancy leveson

--
Nancy Leveson