Engineering PapersSearch

Engineering topics

Holloway, C. Michael

Publications and source records attributed to Holloway, C. Michael.

At least 19 records

Assurance Arguments for the Non-Graphically-Inclined: Two Approaches

We introduce and discuss two approaches to presenting assurance arguments. One approach is based on a monograph structure, while the other is based on a tabular structure. In today's research and academic setting, assurance cases often use a graphical notation; however for people who are not graphically inclined, these notations can be difficult to read. This document proposes, outlines, explains, and presents examples of two non-graphical assurance argument notations that may be appropriate for non-graphically-inclined readers and also provide argument writers with freedom to add details and manipulate an argument in multiple ways.

Heavner, Emily

An Investigation of Proposed Techniques for Quantifying Confidence in Assurance Arguments

The use of safety cases in certification raises the question of assurance argument sufficiency and the issue of confidence (or uncertainty) in the argument's claims. Some researchers propose to model confidence quantitatively and to calculate confidence in argument conclusions. We know of little evidence to suggest that any proposed technique would deliver trustworthy results when implemented by system safety practitioners. Proponents do not usually assess the efficacy of their techniques through controlled experiment or historical study. Instead, they present an illustrative example where the calculation delivers a plausible result. In this paper, we review current proposals, claims made about them, and evidence advanced in favor of them. We then show that proposed techniques can deliver implausible results in some cases. We conclude that quantitative confidence techniques require further validation before they should be recommended as part of the basis for deciding whether an assurance argument justifies fielding a critical system.

Graydon, Patrick J.

Planning the Unplanned Experiment: Assessing the Efficacy of Standards for Safety Critical Software

We need well-founded means of determining whether software is t for use in safety-critical applications. While software in industries such as aviation has an excellent safety record, the fact that software aws have contributed to deaths illustrates the need for justi ably high con dence in software. It is often argued that software is t for safety-critical use because it conforms to a standard for software in safety-critical systems. But little is known about whether such standards `work.' Reliance upon a standard without knowing whether it works is an experiment; without collecting data to assess the standard, this experiment is unplanned. This paper reports on a workshop intended to explore how standards could practicably be assessed. Planning the Unplanned Experiment: Assessing the Ecacy of Standards for Safety Critical Software (AESSCS) was held on 13 May 2014 in conjunction with the European Dependable Computing Conference (EDCC). We summarize and elaborate on the workshop's discussion of the topic, including both the presented positions and the dialogue that ensued.

Graydon, Patrick J.

Explicate '78: Uncovering the Implicit Assurance Case in DO-178C

For about two decades, compliance with Software Considerations in Airborne Systems and Equipment Certification (DO-178B/ED-12B) has been the primary means for receiving regulatory approval for using software on commercial airplanes. A new edition of the standard, DO-178C/ED-12C, was published in December 2011, and recognized by regulatory bodies in 2013. The purpose remains unchanged: to provide guidance 'for the production of software for airborne systems and equipment that performs its intended function with a level of confidence in safety that complies with airworthiness requirements.' The text of the guidance does not directly explain how its collection of objectives contributes to achieving this purpose; thus, the assurance case for the document is implicit. This paper presents an explicit assurance case developed as part of research jointly sponsored by the Federal Aviation Administration and the National Aeronautics and Space Administration.

Holloway, C. Michael

Neither Pollyanna nor Chicken Little: Thoughts on the Ethics of Automation

This paper has raised issues concerning the ethics of automation in aviation systems, and outlined ways of thinking about the issues that may help in ethical decision making. It is very easy to be carried along by technology and the Pollyanna view, but just because we can do something, doesn't mean we should - which is perhaps a little milder than the Chicken Little view. Both views have merits, and we would view ethical decisions as ones that more appropriately balance or reconcile these conflicting viewpoints. We have set out some of the background to the problems of automation in aviation systems, but are aware that there is much more that could be said (considering military UAS, for example). We hope, however, that the brief introduction provides a foundation for the ethical questions that we have set out. The underlying aim in proposing ESCs is to make understanding ethical issues easier so that ethically-informed decisions can be made. Whilst we have not linked the discussion directly back to specific ethical decisions, we believe that making explicit those issues on which such judgments are based is a contribution to ethically informed decision making. We also believe that the four principles set out by the RAEng are reflected in this approach. We acknowledge that what we have set out, especially the ideas of ESC, goes some way beyond current practice and principles and there are significant technical issues to resolve before such an approach could be implemented. It is hoped, however, that the ideas will help improve the production and presentation of safety cases in a range of industries not just aviation - a Pollyanna view, of course!

Holloway, C. Michael

Making the Implicit Explicit: Towards an Assurance Case for DO-178C

For about two decades, compliance with Software Considerations in Airborne Systems and Equipment Certification (DO-178B) has been the primary means for receiving regulatory approval for using software on commercial airplanes. A new edition of the standard, DO-178C, was published in December 2011, and regulatory bodies have started the process towards recognizing this edition. The stated purpose of DO-178C remains unchanged from its predecessor: providing guidance “for the production of software for airborne systems and equipment that performs its intended function with a level of confidence in safety that complies with airworthiness requirements.” Within the text of the guidance, little or no rationale is given for how a particular objective or collection of objectives contributes to achieving this purpose. Thus the assurance case for the document is implicit. This paper discusses a current effort to make the implicit explicit. In particular, the paper describes the current status of the research seeking to identify the specific arguments contained in, or implied by, the DO-178C guidance that implicitly justify the assumption that the document meets its stated purpose.

Holloway, C. Michael

Analyzing a Mid-Air Collision Over the Hudson River

On August 8, 2009, a private airplane collided with a sightseeing helicopter over the Hudson River near Hoboken, New Jersey. All three people aboard the airplane, the pilot and two passengers, and all six people aboard the helicopter, the pilot and five passengers, were killed. The National Transportation Safety Board report on the accident identified inherent limitations of the see-and-avoid concept, inadequate regulations, and errors by the pilots and an air traffic controller as causing or contributing to the accident. This paper presents the results of analyzing the accident using the Systems-Theoretic Accident Model and Processes (STAMP) approach to determining accident causation.

Brown, Sean

Reducing Our Ignorance: Finding Answers to Certain Epistemic Questions for Software Systems

In previous papers, we asserted that software system safety is primarily concerned with epistemic questions, that is, questions concerning knowledge and the degree of confidence that can be placed in that knowledge. We also enumerated a set of 21 foundational epistemic questions, discussed some of the difficulties that exist in answering these questions adequately today, and speculated briefly on possible research that may provide improved confidence in the sufficiency of answers in the future. This paper focuses on three of the foundational questions. For each of these questions, current answers are discussed and potential research is proposed to help increase the justifiable level of confidence.

Holloway, C. Michael

A Possible Approach for Addressing Neglected Human Factors Issues of Systems Engineering

The increasing complexity of safety-critical applications has led to the introduction of decision support tools in the transportation and process industries. Automation has also been introduced to support operator intervention in safety-critical applications. These innovations help reduce overall operator workload, and filter application data to maximize the finite cognitive and perceptual resources of system operators. However, these benefits do not come without a cost. Increased computational support for the end-users of safety-critical applications leads to increased reliance on engineers to monitor and maintain automated systems and decision support tools. This paper argues that by focussing on the end-users of complex applications, previous research has tended to neglect the demands that are being placed on systems engineers. The argument is illustrated through discussing three recent accidents. The paper concludes by presenting a possible strategy for building and using highly automated systems based on increased attention by management and regulators, improvements in competency and training for technical staff, sustained support for engineering team resource management, and the development of incident reporting systems for infrastructure failures. This paper represents preliminary work, about which we seek comments and suggestions.

Johnson, Christopher W.

The Role of Trust and Interaction in Global Positioning System Related Accidents

The Global Positioning System (GPS) uses a network of satellites to calculate the position of a receiver over time. This technology has revolutionized a wide range of safety-critical industries and leisure applications. These systems provide diverse benefits; supplementing the users existing navigation skills and reducing the uncertainty that often characterizes many route planning tasks. GPS applications can also help to reduce workload by automating tasks that would otherwise require finite cognitive and perceptual resources. However, the operation of these systems has been identified as a contributory factor in a range of recent accidents. Users often come to rely on GPS applications and, therefore, fail to notice when they develop faults or when errors occur in the other systems that use the data from these systems. Further accidents can stem from the over confidence that arises when users assume automated warnings will be issued when they stray from an intended route. Unless greater attention is paid to the role of trust and interaction in GPS applications then there is a danger that we will see an increasing number of these failures as positioning technologies become integral in the functioning of increasing numbers of applications.

Johnson, Chris W.

A Taxonomy of Fallacies in System Safety Arguments

Safety cases are gaining acceptance as assurance vehicles for safety-related systems. A safety case documents the evidence and argument that a system is safe to operate; however, logical fallacies in the underlying argument may undermine a system s safety claims. Removing these fallacies is essential to reduce the risk of safety-related system failure. We present a taxonomy of common fallacies in safety arguments that is intended to assist safety professionals in avoiding and detecting fallacious reasoning in the arguments they develop and review. The taxonomy derives from a survey of general argument fallacies and a separate survey of fallacies in real-world safety arguments. Our taxonomy is specific to safety argumentation, and it is targeted at professionals who work with safety arguments but may lack formal training in logic or argumentation. We discuss the rationale for the selection and categorization of fallacies in the taxonomy. In addition to its applications to the development and review of safety cases, our taxonomy could also support the analysis of system failures and promote the development of more robust safety case patterns.

Greenwell, William S.

From Bridges and Rockets, Lessons for Software Systems

Although differences exist between building software systems and building physical structures such as bridges and rockets, enough similarities exist that software engineers can learn lessons from failures in traditional engineering disciplines. This paper draws lessons from two well-known failures the collapse of the Tacoma Narrows Bridge in 1940 and the destruction of the space shuttle Challenger in 1986 and applies these lessons to software system development. The following specific applications are made: (1) the verification and validation of a software system should not be based on a single method, or a single style of methods; (2) the tendency to embrace the latest fad should be overcome; and (3) the introduction of software control into safety-critical systems should be done cautiously.

Holloway, C. Michael

Considering Object Oriented Technology in Aviation Applications

Few developers of commercial aviation software products are using object-oriented technology (OOT), despite its popularity in some other industries. Safety concerns about using OOT in critical applications, uncertainty about how to comply with regulatory requirements, and basic conservatism within the aviation community have been factors behind this caution. The Federal Aviation Administration (FAA) and the National Aeronautics and Space Administration (NASA) have sponsored research to investigate and workshops to discuss safety and certification concerns about OOT and to develop recommendations for safe use. Two Object Oriented Technology in Aviation (OOTiA) workshops have been held and numerous issues and comments about the effect of OOT features and languages have been collected. This paper gives a high level overview of the OOTiA project, and discusses selected specific results from the March 2003 workshop. In particular, results in the form of questions to consider before making the decision to use OOT are presented.

Hayhurst, Kelly J.

Issues in Software System Safety: Polly Ann Smith Co. versus Ned I. Ludd

This paper is a work of fiction, but it is fiction with a very real purpose: to stimulate careful thought and friendly discussion about some questions for which thought is often careless and discussion is often unfriendly. To accomplish this purpose, the paper creates a fictional legal case. The most important issue in this fictional case is whether certain proffered expert testimony about software engineering for safety critical systems should be admitted. Resolving this issue requires deciding the extent to which current practices and research in software engineering, especially for safety-critical systems, can rightly be considered based on knowledge, rather than opinion.

Holloway, C. Michael

Software System Safety and the NASA Aeronautics Blueprint

NASA's Aeronautics Blueprint lays out a research agenda for the Agency s aeronautics program. The word software appears only four times in this Blueprint, but the critical importance of safe and correct software to the fulfillment of the proposed research is evident on almost every page. Most of the technology solutions proposed to address challenges in aviation are software dependent technologies. Of the fifty-two specific technology solutions described in the Blueprint, forty-one depend, at least in part, on software for success. For thirty-five of these forty-one, software is not only critical to success, but also to human safety. That is, implementing the technology solutions will require using software in such a way that it may, if not specified, designed, and implemented properly, lead to fatal accidents. These results have at least two implications for the research based on the Blueprint: (1) knowledge about the current state-of-the-art and state-of-the-practice in software engineering and software system safety is essential, and (2) research into current unsolved problems in these software disciplines is also essential.

Holloway, C. Michael

Lfm2000: Fifth NASA Langley Formal Methods Workshop

This is the proceedings of Lfm2000: Fifth NASA Langley Formal Methods Workshop. The workshop was held June 13-15, 2000, in Williamsburg, Virginia. See the web site for complete information about the event.

Holloway, C. Michael