• DocumentCode
    2873319
  • Title

    Controlling the risk of COTS via application programming interfaces

  • Author

    O´Halloran, Colin

  • Author_Institution
    Defence Res. Agency, Malvern, UK
  • fYear
    1997
  • fDate
    35458
  • Firstpage
    42522
  • Lastpage
    42523
  • Abstract
    There are various approaches to building critical systems. One approach is the use of fault-tolerant software architectures. This approach can be difficult even when components have been developed under a customer´s control. When the detailed behaviour of the component is unknown, which is often the case with a COTS (commercial off-the-shelf) component, then providing appropriate recovery actions becomes even more difficult. To be able to tolerate erroneous behaviours, application programming interfaces (APIs) must be identified because it is through these that a component expresses its behaviour. The more information about an API that is known, the more will be known about the possible behaviours of a component and how erroneous behaviour could be tolerated. An approach to accepting safety-critical systems consisting of COTS software is the use of static analysis techniques to determine desirable properties of components. Even when a software component is analysed, the properties of that component need to be composed together with the other components to determine the overall system properties. Again, the key is to determine the APIs and how components interact through them in order to establish compositional behaviours. A COTS component tends to have more functionality than required for a particular system because it is more general-purpose. This provides more ways for unexpected behaviours to arise and threaten the integrity of a system. By identifying unwanted APIs and policing them, the extra functionality can sometimes be limited and the vulnerability of the system to failure reduced
  • Keywords
    software packages; API; COTS risk control; application programming interfaces; commercial off-the-shelf software components; compositional behaviours; erroneous behaviours; fault-tolerant software architectures; functionality; general-purpose software; recovery actions; safety-critical systems; static analysis; system failure vulnerability; system integrity; unexpected behaviours;
  • fLanguage
    English
  • Publisher
    iet
  • Conference_Titel
    Cots and Safety Critical Systems (Digest No. 1997/013), IEE Colloquium on
  • Conference_Location
    London
  • Type

    conf

  • DOI
    10.1049/ic:19970096
  • Filename
    599249