|
In addition to the use of importance sampling,
there is another view that can be taken of high integrity systems where reliability
is very high and there is relatively little failure data on which evaluations can
be made. This method involves a qualitative evaluation of the data and the search
for trends. This is not a technology so much as a methodology, as extensive experience
and insight are required for its success. An example of findings we have made using
this approach is in the Space Shuttle avionics: This software is highly mature and
was developed with great care. This is demonstrated by the fact that the predominant
cause of failures are multiply occurring unusual events or exception conditions
as can be caused by mechanical or electric failures. The Removal of the remaining
errors therefore requires the development of test cases that stress this trend:
not only single unusual events, but rather focus on multiple rare conditions.
|
|