首页 > 最新文献

2011 IEEE 13th International Symposium on High-Assurance Systems Engineering最新文献

英文 中文
An Availability Model of a Virtual TMR System with Applications in Cloud/Cluster Computing 基于云/集群计算的虚拟TMR系统可用性模型
Ricardo Paharsingh, O. Das
Three important factors in dependable computing are cost, error correction and high availability. In this paper we will focus on assessing a proposed model that encapsulates all three important factors and a virtual architecture that can be implemented in the IaaS layer of cloud computing. The proposed model will be assessed against a popular existing architecture (Triple Modular Redundant System TMR) and the availability analysis done with Fault-Trees combined with Markov Chains. These experiments will demonstrate that the virtualization of the TMR system using the architecture that we have proposed, will achieve almost the same level of availability/reliability and cost, along with the inherent advantages of virtual systems. Advantages include faster system restart, efficient use of resources and migration.
可靠计算的三个重要因素是成本、纠错和高可用性。在本文中,我们将重点评估一个提议的模型,该模型封装了所有三个重要因素和一个可以在云计算的IaaS层实现的虚拟架构。提出的模型将根据现有的流行架构(三模冗余系统TMR)进行评估,并使用故障树和马尔可夫链结合进行可用性分析。这些实验将证明,使用我们提出的体系结构的TMR系统虚拟化将实现几乎相同的可用性/可靠性和成本水平,以及虚拟系统的固有优势。优点包括更快的系统重启,有效地利用资源和迁移。
{"title":"An Availability Model of a Virtual TMR System with Applications in Cloud/Cluster Computing","authors":"Ricardo Paharsingh, O. Das","doi":"10.1109/HASE.2011.11","DOIUrl":"https://doi.org/10.1109/HASE.2011.11","url":null,"abstract":"Three important factors in dependable computing are cost, error correction and high availability. In this paper we will focus on assessing a proposed model that encapsulates all three important factors and a virtual architecture that can be implemented in the IaaS layer of cloud computing. The proposed model will be assessed against a popular existing architecture (Triple Modular Redundant System TMR) and the availability analysis done with Fault-Trees combined with Markov Chains. These experiments will demonstrate that the virtualization of the TMR system using the architecture that we have proposed, will achieve almost the same level of availability/reliability and cost, along with the inherent advantages of virtual systems. Advantages include faster system restart, efficient use of resources and migration.","PeriodicalId":403140,"journal":{"name":"2011 IEEE 13th International Symposium on High-Assurance Systems Engineering","volume":"16 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2011-11-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"121776844","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 3
An Early Design Stage UML-Based Safety Analysis Approach for High Assurrance Software Systems 基于uml的高保证软件系统早期设计阶段安全分析方法
Chetan Mutha, C. Smidts
High-assurance computer systems fulfill security, safety, fault-tolerant, and real-time properties. Analysis of these properties is typically performed in isolation. An integrated analysis of all the properties is a challenge that can be addressed by expressing these properties in a common integrated framework. The Unified Modeling Language is a standard modeling language which exhibits such a capability. In this paper we focus on using the Unified Modeling Language to analyze the safety properties of high-assurance systems. In particular we are interested in the study of software faults propagation and their functional level effects. In previous work we have developed the Failure Propagation and Simulation Approach to study whether a particular fault will propagate through the design and cause system-level functional failures. Mapping between different Unified Modeling Language diagrams is the central concept behind the approach. This paper briefly introduces the Failure Propagation and Simulation Approach and presents in detail the executable models developed to automate the simulation process. These executable models are built using the notations of the Event Sequence Diagram, one of the established reliability and safety analysis techniques for sequence progression.
高保证计算机系统具有安全、安全、容错和实时性。这些特性的分析通常是单独进行的。对所有属性进行集成分析是一项挑战,可以通过在公共集成框架中表达这些属性来解决。统一建模语言是一种标准的建模语言,它展示了这种能力。本文的重点是利用统一建模语言对高保证系统的安全特性进行分析。我们特别感兴趣的是软件故障传播及其功能级效应的研究。在之前的工作中,我们开发了故障传播和仿真方法来研究特定故障是否会通过设计传播并导致系统级功能故障。不同统一建模语言图之间的映射是该方法背后的核心概念。本文简要介绍了故障传播和仿真方法,并详细介绍了为实现仿真过程自动化而开发的可执行模型。这些可执行模型是使用事件序列图(Event Sequence Diagram)的符号构建的,事件序列图是用于序列进展的已建立的可靠性和安全性分析技术之一。
{"title":"An Early Design Stage UML-Based Safety Analysis Approach for High Assurrance Software Systems","authors":"Chetan Mutha, C. Smidts","doi":"10.1109/HASE.2011.37","DOIUrl":"https://doi.org/10.1109/HASE.2011.37","url":null,"abstract":"High-assurance computer systems fulfill security, safety, fault-tolerant, and real-time properties. Analysis of these properties is typically performed in isolation. An integrated analysis of all the properties is a challenge that can be addressed by expressing these properties in a common integrated framework. The Unified Modeling Language is a standard modeling language which exhibits such a capability. In this paper we focus on using the Unified Modeling Language to analyze the safety properties of high-assurance systems. In particular we are interested in the study of software faults propagation and their functional level effects. In previous work we have developed the Failure Propagation and Simulation Approach to study whether a particular fault will propagate through the design and cause system-level functional failures. Mapping between different Unified Modeling Language diagrams is the central concept behind the approach. This paper briefly introduces the Failure Propagation and Simulation Approach and presents in detail the executable models developed to automate the simulation process. These executable models are built using the notations of the Event Sequence Diagram, one of the established reliability and safety analysis techniques for sequence progression.","PeriodicalId":403140,"journal":{"name":"2011 IEEE 13th International Symposium on High-Assurance Systems Engineering","volume":"43 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2011-11-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"125496950","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 6
Benchmarking Embedded Software Development Project Performance 对嵌入式软件开发项目性能进行基准测试
Michael F. Siok, J. Tian
Day-by-day managers charged with the development of complex embedded systems struggle with the evolving quality and productivity of software. Measurement and reporting of key software project metrics helps these managers visualize software development performance but oftentimes the data and subsequent analyses needed to make decisions is limited at best. Further, the software data needed from multiple software projects across the organization necessary to derive, plan, and implement longer-term strategic and tactical plans for the software organization is difficult to aggregate, organize, and report. This paper provides a way, using project metrics and data envelopment analysis, for a software organization to perform a comparative analysis of software projects, identify strengths and weaknesses of each given a specific software production efficiency model, and identify best practices that should be brought forward within the organization for further study and application on future software projects. Using this technique, a company developing product software can reliably audit and systematically adjust their business processes to continually improve and keep competitive their 'business of software.'
每天负责开发复杂嵌入式系统的管理人员都在与不断发展的软件质量和生产力作斗争。关键软件项目指标的度量和报告帮助这些管理人员可视化软件开发性能,但是通常做出决策所需的数据和后续分析最多是有限的。此外,来自跨组织的多个软件项目所需的软件数据很难汇总、组织和报告,这些数据是为软件组织派生、计划和实现长期战略和战术计划所必需的。本文提供了一种方法,使用项目度量和数据包络分析,为软件组织执行软件项目的比较分析,确定每个特定软件生产效率模型的优势和劣势,并确定应该在组织内提出的最佳实践,以便在未来的软件项目中进一步研究和应用。使用这种技术,开发产品软件的公司可以可靠地审计和系统地调整其业务流程,以不断改进并保持其“软件业务”的竞争力。
{"title":"Benchmarking Embedded Software Development Project Performance","authors":"Michael F. Siok, J. Tian","doi":"10.1109/HASE.2011.59","DOIUrl":"https://doi.org/10.1109/HASE.2011.59","url":null,"abstract":"Day-by-day managers charged with the development of complex embedded systems struggle with the evolving quality and productivity of software. Measurement and reporting of key software project metrics helps these managers visualize software development performance but oftentimes the data and subsequent analyses needed to make decisions is limited at best. Further, the software data needed from multiple software projects across the organization necessary to derive, plan, and implement longer-term strategic and tactical plans for the software organization is difficult to aggregate, organize, and report. This paper provides a way, using project metrics and data envelopment analysis, for a software organization to perform a comparative analysis of software projects, identify strengths and weaknesses of each given a specific software production efficiency model, and identify best practices that should be brought forward within the organization for further study and application on future software projects. Using this technique, a company developing product software can reliably audit and systematically adjust their business processes to continually improve and keep competitive their 'business of software.'","PeriodicalId":403140,"journal":{"name":"2011 IEEE 13th International Symposium on High-Assurance Systems Engineering","volume":"225 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2011-11-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"132808777","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 1
So Much to Learn from One Accident Crash of 737 on 25 February 2009 从2009年2月25日波音737坠机事故中吸取的教训
H. Hecht
Turkish Airlines Flight 1951 crashed short of its destination runway at Schiphol Airport, Amsterdam, Netherlands on February 25, 2009. Nine people lost their lives, 177 were injured, and the aircraft was a complete loss. There was an equipment failure in the left radio altimeter that caused the auto-throttle system to go into retard flare mode in anticipation of immediate landing when the aircraft was still near 2000 ft above terrain, There were indications and warnings of this condition to the crew but they were ignored. The throttle retardation was also temporarily masked by the aircraft being directed to intercept the localizer from above, a highly unusual procedure. The investigation found numerous instances of low altitude readings on the accident aircraft as well as on others. Also, the accident aircraft had experienced two instances of throttle retardation on recent flights. Poor reporting practices led the manufacturer and the certifying authorities to underestimate the prevalence of this failure pattern. It is concluded that in many instances actions and design decisions were based on the assumption further conditions will be within the normal envelope. This is a dangerous assumption that must be avoided if we want to maintain the fine safety record of commercial aviation.
土耳其航空公司1951号航班在2009年2月25日荷兰阿姆斯特丹史基浦机场的目的地跑道上坠毁。9人丧生,177人受伤,这架飞机完全失败了。左侧无线电高度表出现了设备故障,导致自动油门系统进入延迟闪光模式,预计飞机将在距离地面2000英尺的地方立即着陆。机组人员收到了这种情况的指示和警告,但他们被忽视了。油门减速也被飞机暂时掩盖,被指示从上方拦截航向仪,一个非常不寻常的程序。调查发现,事故飞机和其他飞机上都有很多低空读数的例子。此外,事故飞机在最近的飞行中经历了两次油门减速的情况。不良的报告实践导致制造商和认证机构低估了这种故障模式的普遍性。结论是,在许多情况下,行动和设计决策是基于进一步的条件将在正常范围内的假设。如果我们想保持商业航空的良好安全记录,这是一个必须避免的危险假设。
{"title":"So Much to Learn from One Accident Crash of 737 on 25 February 2009","authors":"H. Hecht","doi":"10.1109/HASE.2011.45","DOIUrl":"https://doi.org/10.1109/HASE.2011.45","url":null,"abstract":"Turkish Airlines Flight 1951 crashed short of its destination runway at Schiphol Airport, Amsterdam, Netherlands on February 25, 2009. Nine people lost their lives, 177 were injured, and the aircraft was a complete loss. There was an equipment failure in the left radio altimeter that caused the auto-throttle system to go into retard flare mode in anticipation of immediate landing when the aircraft was still near 2000 ft above terrain, There were indications and warnings of this condition to the crew but they were ignored. The throttle retardation was also temporarily masked by the aircraft being directed to intercept the localizer from above, a highly unusual procedure. The investigation found numerous instances of low altitude readings on the accident aircraft as well as on others. Also, the accident aircraft had experienced two instances of throttle retardation on recent flights. Poor reporting practices led the manufacturer and the certifying authorities to underestimate the prevalence of this failure pattern. It is concluded that in many instances actions and design decisions were based on the assumption further conditions will be within the normal envelope. This is a dangerous assumption that must be avoided if we want to maintain the fine safety record of commercial aviation.","PeriodicalId":403140,"journal":{"name":"2011 IEEE 13th International Symposium on High-Assurance Systems Engineering","volume":"91 11 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2011-11-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"132896820","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 2
A Behavioral Analysis Approach for Efficient Partial Order Reduction 一种高效偏阶约简的行为分析方法
Yingying Zhang, Emmanuel Rodriguez, Hao Zheng, C. Myers
Partial order reduction is essential to address state explosion when verifying concurrent systems by reducing states irrelevant to the verification results. However, traditional static approaches by analyzing system model structures often do not work well. To address such problem, this paper presents a new behavioral analysis approach where a compositional reach ability analysis method is used to generate the over-approximate state spaces for all modules in a system, and then the independent transitions necessary for the partial order reduction are computed by examining these state spaces. Compared to the static analysis approaches, the independent transitions computed are more refined and accurate. The experimental results on some examples show that the presented approach is promising.
在验证并发系统时,通过减少与验证结果无关的状态来解决状态爆炸问题是必要的。然而,通过分析系统模型结构的传统静态方法往往不能很好地工作。为了解决这一问题,本文提出了一种新的行为分析方法,该方法使用组合到达能力分析方法生成系统中所有模块的过近似状态空间,然后通过检查这些状态空间来计算系统的偏序约简所需要的独立转移。与静态分析方法相比,计算的独立过渡更加精细和准确。一些算例的实验结果表明,该方法是可行的。
{"title":"A Behavioral Analysis Approach for Efficient Partial Order Reduction","authors":"Yingying Zhang, Emmanuel Rodriguez, Hao Zheng, C. Myers","doi":"10.1109/HASE.2011.15","DOIUrl":"https://doi.org/10.1109/HASE.2011.15","url":null,"abstract":"Partial order reduction is essential to address state explosion when verifying concurrent systems by reducing states irrelevant to the verification results. However, traditional static approaches by analyzing system model structures often do not work well. To address such problem, this paper presents a new behavioral analysis approach where a compositional reach ability analysis method is used to generate the over-approximate state spaces for all modules in a system, and then the independent transitions necessary for the partial order reduction are computed by examining these state spaces. Compared to the static analysis approaches, the independent transitions computed are more refined and accurate. The experimental results on some examples show that the presented approach is promising.","PeriodicalId":403140,"journal":{"name":"2011 IEEE 13th International Symposium on High-Assurance Systems Engineering","volume":"43 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2011-11-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"131327300","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Smart Vibration Monitoring System for an Ocean Turbine 海洋水轮机智能振动监测系统
Mustapha Mjit, P. Beaujean, D. Vendittis
This paper describes a Smart Vibration Monitoring System (SVMS) developed as an effective way to reduce equipment losses and enhance safety, efficiency, reliability, availability and long life time duration of an ocean turbine. The system utilizes advanced signal processing and analysis techniques to evaluate the health of a machine and identify incipient anomalies (faults) and evaluate their severity relative to the machine's condition. The existing system and planned improvements are described and discussed. The primary function of the SVMS is an automatic machinery fault detection and diagnosis based on real time processing and analysis of vibration data. The SVMS basically performs the same functions as a vibration analyst would for post processing of off-line data. The SVMS automatically sends a warning message to a cell phone and to an email address as soon as it detects a fault that is developing within the machine. The message will contain a generic identification of the fault.
本文介绍了一种智能振动监测系统(SVMS),该系统是减少设备损失,提高海洋水轮机安全性、效率、可靠性、可用性和长寿命的有效途径。该系统利用先进的信号处理和分析技术来评估机器的健康状况,识别早期的异常(故障),并评估其相对于机器状况的严重程度。对现有系统和计划中的改进进行了描述和讨论。支持向量机的主要功能是基于对振动数据的实时处理和分析,实现机械故障的自动检测和诊断。支持向量机基本上执行与振动分析人员对离线数据进行后处理相同的功能。一旦检测到机器内部出现故障,SVMS就会自动向手机和电子邮件地址发送警告信息。该消息将包含故障的一般标识。
{"title":"Smart Vibration Monitoring System for an Ocean Turbine","authors":"Mustapha Mjit, P. Beaujean, D. Vendittis","doi":"10.1109/HASE.2011.34","DOIUrl":"https://doi.org/10.1109/HASE.2011.34","url":null,"abstract":"This paper describes a Smart Vibration Monitoring System (SVMS) developed as an effective way to reduce equipment losses and enhance safety, efficiency, reliability, availability and long life time duration of an ocean turbine. The system utilizes advanced signal processing and analysis techniques to evaluate the health of a machine and identify incipient anomalies (faults) and evaluate their severity relative to the machine's condition. The existing system and planned improvements are described and discussed. The primary function of the SVMS is an automatic machinery fault detection and diagnosis based on real time processing and analysis of vibration data. The SVMS basically performs the same functions as a vibration analyst would for post processing of off-line data. The SVMS automatically sends a warning message to a cell phone and to an email address as soon as it detects a fault that is developing within the machine. The message will contain a generic identification of the fault.","PeriodicalId":403140,"journal":{"name":"2011 IEEE 13th International Symposium on High-Assurance Systems Engineering","volume":"5 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2011-11-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"121742337","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 7
Validation of Object Recognition Framework on Android Mobile Platform Android移动平台上目标识别框架的验证
V. Tyagi, A. Pandya, Ankur Agarwal, B. Alhalabi
In recent years there has been great interest in implementing object recognition frame work on mobile phones. This has stemmed from the fact the advances in object recognition algorithm and mobile phone capabilities have built a congenial ecosystem. Application developers on mobile platforms are trying to utilize the object recognition technology to build better human computer interfaces. This approach is in the nascent phase and proper application framework is required. In this paper, we propose a framework to overcome design challenges and provide an evaluation methodology to assess the system performance. We use the emerging Android mobile platform to implement and test the framework. We performed a case study using the proposal and reported the test result. This assessment will help developers make wise decisions about their application design. Furthermore, the Android API developers could use this information to provide better interfaces to the third party developers. The design and evaluation methodology could be extended to other mobile platforms for a wider consumer base.
近年来,人们对在移动电话上实现目标识别框架产生了极大的兴趣。这是因为物体识别算法和移动电话功能的进步建立了一个和谐的生态系统。移动平台上的应用程序开发人员正试图利用物体识别技术来构建更好的人机界面。这种方法还处于萌芽阶段,需要适当的应用程序框架。在本文中,我们提出了一个框架来克服设计挑战,并提供了评估系统性能的评估方法。我们使用新兴的Android移动平台来实现和测试该框架。我们使用该建议执行了一个案例研究,并报告了测试结果。这种评估将帮助开发人员对他们的应用程序设计做出明智的决策。此外,Android API开发人员可以使用这些信息为第三方开发人员提供更好的接口。设计和评估方法可以扩展到其他移动平台,以获得更广泛的消费者基础。
{"title":"Validation of Object Recognition Framework on Android Mobile Platform","authors":"V. Tyagi, A. Pandya, Ankur Agarwal, B. Alhalabi","doi":"10.1109/HASE.2011.62","DOIUrl":"https://doi.org/10.1109/HASE.2011.62","url":null,"abstract":"In recent years there has been great interest in implementing object recognition frame work on mobile phones. This has stemmed from the fact the advances in object recognition algorithm and mobile phone capabilities have built a congenial ecosystem. Application developers on mobile platforms are trying to utilize the object recognition technology to build better human computer interfaces. This approach is in the nascent phase and proper application framework is required. In this paper, we propose a framework to overcome design challenges and provide an evaluation methodology to assess the system performance. We use the emerging Android mobile platform to implement and test the framework. We performed a case study using the proposal and reported the test result. This assessment will help developers make wise decisions about their application design. Furthermore, the Android API developers could use this information to provide better interfaces to the third party developers. The design and evaluation methodology could be extended to other mobile platforms for a wider consumer base.","PeriodicalId":403140,"journal":{"name":"2011 IEEE 13th International Symposium on High-Assurance Systems Engineering","volume":"1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2011-11-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"130304614","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 3
Transforming Privacy Policies to Auditing Specifications 将隐私策略转换为审计规范
Debmalya Biswas, Valtteri Niemi
With more and more personal data being collected and stored by service providers, there is an increasing need to ensure that their usage is compliant with privacy regulations. We consider the specific scenario where policies are defined in metric temporal logic and audited against the database usage logs. Previous works have shown that this can indeed be achieved in an efficient manner for a very expressive set of policies. One of the main ingredients of such an auditing process is the availability of sufficient database logs. Currently, it is a manual process to first determine the logs needed, and then come up with the necessary auditing specifications to generate them. This is not only a time consuming process but can be erroneous as well, leading to either insufficient or redundant logging. Logging in general is costly as it is an overhead on the real-time database performance, and hence redundant logging is not an alternative either. Our contribution in this work is to streamline the log generation process by deriving the auditing specifications directly from the policies to be audited. We also show how the required logging can be minimized based on the temporal constraints specified in the policies. Given privacy policies as input, the output of the proposed tool is the corresponding auditing specifications that can be installed directly in the databases, to produce logs that are both minimal and sufficient to audit the given policies. The tool has been implemented and tested in a real-life scenario.
随着服务提供商收集和存储越来越多的个人数据,越来越需要确保这些数据的使用符合隐私法规。我们考虑在度量时态逻辑中定义策略并根据数据库使用日志进行审计的特定场景。以前的工作表明,这确实可以以一种有效的方式实现一套非常富有表现力的政策。这种审计过程的主要组成部分之一是提供足够的数据库日志。目前,这是一个手动过程,首先确定所需的日志,然后提出必要的审计规范来生成它们。这不仅是一个耗时的过程,而且可能是错误的,导致日志记录不足或冗余。日志记录通常代价高昂,因为它会增加实时数据库性能的开销,因此冗余日志记录也不是一种替代方法。我们在这项工作中的贡献是通过直接从要审计的策略中派生审计规范来简化日志生成过程。我们还展示了如何根据策略中指定的时间约束最小化所需的日志记录。将隐私策略作为输入,建议的工具的输出是相应的审计规范,这些规范可以直接安装在数据库中,以生成最少且足以审计给定策略的日志。该工具已在实际场景中实现和测试。
{"title":"Transforming Privacy Policies to Auditing Specifications","authors":"Debmalya Biswas, Valtteri Niemi","doi":"10.1109/HASE.2011.51","DOIUrl":"https://doi.org/10.1109/HASE.2011.51","url":null,"abstract":"With more and more personal data being collected and stored by service providers, there is an increasing need to ensure that their usage is compliant with privacy regulations. We consider the specific scenario where policies are defined in metric temporal logic and audited against the database usage logs. Previous works have shown that this can indeed be achieved in an efficient manner for a very expressive set of policies. One of the main ingredients of such an auditing process is the availability of sufficient database logs. Currently, it is a manual process to first determine the logs needed, and then come up with the necessary auditing specifications to generate them. This is not only a time consuming process but can be erroneous as well, leading to either insufficient or redundant logging. Logging in general is costly as it is an overhead on the real-time database performance, and hence redundant logging is not an alternative either. Our contribution in this work is to streamline the log generation process by deriving the auditing specifications directly from the policies to be audited. We also show how the required logging can be minimized based on the temporal constraints specified in the policies. Given privacy policies as input, the output of the proposed tool is the corresponding auditing specifications that can be installed directly in the databases, to produce logs that are both minimal and sufficient to audit the given policies. The tool has been implemented and tested in a real-life scenario.","PeriodicalId":403140,"journal":{"name":"2011 IEEE 13th International Symposium on High-Assurance Systems Engineering","volume":"1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2011-11-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"129913427","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 15
Animating the Approach of Deriving Operational Semantics from Algebraic Semantics for Web Services 基于代数语义的Web服务操作语义派生方法
Qian Wang, Huibiao Zhu
Web services have became more and more important in these years, and BPEL4WS (BPEL) is a de facto standard for the web service composition and orchestration. It contains several distinct features, including the scope-based compensation and fault handling mechanism. We have already explored the operational semantics and denotational semantics for BPEL, where a set of algebraic laws can be achieved via these two models respectively. Meanwhile, we have also explored the link between the operational semantics and algebraic semantics for BPEL. Our approach was to derive the operational semantics from algebraic semantics. This paper considers the animation approach for the link between operational semantics and algebraic semantics for BPEL. The Logic Programming Language Prolog is applied to support for the development. Firstly we animate the operational semantics for BPEL. Our approach for deriving operational semantics from algebraic semantics proceeds through head normal form. Secondly, we animate the algebraic laws for BPEL. Based on this, we animate the generation of head normal form for each program. Four typical forms are introduced for defining head normal form. Thirdly, we explore the animation for deriving operational semantics from head normal form. From various test results, the first and third exploration show that the soundness and completeness for the operational semantics from the algebraic semantics for BPEL.
近年来,Web服务变得越来越重要,BPEL4WS (BPEL)是Web服务组合和编排的事实上的标准。它包含几个不同的特性,包括基于范围的补偿和故障处理机制。我们已经探讨了BPEL的操作语义和指称语义,其中可以分别通过这两个模型实现一组代数定律。同时,我们还探讨了BPEL的操作语义和代数语义之间的联系。我们的方法是从代数语义推导出运算语义。本文考虑了用于BPEL的操作语义和代数语义之间链接的动画方法。应用逻辑程序设计语言Prolog进行开发支持。首先,我们动画化BPEL的操作语义。我们从代数语义推导运算语义的方法是通过头范式进行的。其次,我们将BPEL的代数定律赋予动画。在此基础上,对每个程序的头部形态进行动画生成。介绍了确定头形的四种典型形式。第三,我们探索了从头部范式中导出操作语义的动画。从各种测试结果来看,第一次和第三次探索显示了BPEL的代数语义与操作语义的可靠性和完整性。
{"title":"Animating the Approach of Deriving Operational Semantics from Algebraic Semantics for Web Services","authors":"Qian Wang, Huibiao Zhu","doi":"10.1109/HASE.2011.56","DOIUrl":"https://doi.org/10.1109/HASE.2011.56","url":null,"abstract":"Web services have became more and more important in these years, and BPEL4WS (BPEL) is a de facto standard for the web service composition and orchestration. It contains several distinct features, including the scope-based compensation and fault handling mechanism. We have already explored the operational semantics and denotational semantics for BPEL, where a set of algebraic laws can be achieved via these two models respectively. Meanwhile, we have also explored the link between the operational semantics and algebraic semantics for BPEL. Our approach was to derive the operational semantics from algebraic semantics. This paper considers the animation approach for the link between operational semantics and algebraic semantics for BPEL. The Logic Programming Language Prolog is applied to support for the development. Firstly we animate the operational semantics for BPEL. Our approach for deriving operational semantics from algebraic semantics proceeds through head normal form. Secondly, we animate the algebraic laws for BPEL. Based on this, we animate the generation of head normal form for each program. Four typical forms are introduced for defining head normal form. Thirdly, we explore the animation for deriving operational semantics from head normal form. From various test results, the first and third exploration show that the soundness and completeness for the operational semantics from the algebraic semantics for BPEL.","PeriodicalId":403140,"journal":{"name":"2011 IEEE 13th International Symposium on High-Assurance Systems Engineering","volume":"30 16","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2011-11-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"120858822","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Efficient System Reliability with Correlated Component Failures 具有相关部件故障的高效系统可靠性
L. Fiondella, S. Rajasekaran, S. Gokhale
Correlated component failures (CCF) degrade system reliability, and hence, these failures must be explicitly incorporated into the reliability analysis process. Several contemporary efforts consider CCF, however, most of these approaches introduce an exponential number of parameters and are computationally intensive because they require a complete characterization of the joint distribution of the components. As a result, these approaches are not scalable and cannot be applied to large systems. This paper presents an efficient approach to analyze system reliability considering CCF. The approach introduces only a quadratic number of parameters and is computationally efficient. The effectiveness of the approach is illustrated through a series of examples. The results indicate that the approach is both simple and efficient and can be applied to large systems.
相关组件故障(CCF)会降低系统的可靠性,因此,这些故障必须明确地纳入可靠性分析过程。一些当代的努力考虑了CCF,然而,这些方法中的大多数都引入了指数数量的参数,并且计算量很大,因为它们需要对组件的联合分布进行完整的表征。因此,这些方法是不可伸缩的,不能应用于大型系统。本文提出了一种考虑CCF的系统可靠性分析方法。该方法只引入二次参数,计算效率高。通过一系列实例说明了该方法的有效性。结果表明,该方法简单有效,可应用于大型系统。
{"title":"Efficient System Reliability with Correlated Component Failures","authors":"L. Fiondella, S. Rajasekaran, S. Gokhale","doi":"10.1109/HASE.2011.31","DOIUrl":"https://doi.org/10.1109/HASE.2011.31","url":null,"abstract":"Correlated component failures (CCF) degrade system reliability, and hence, these failures must be explicitly incorporated into the reliability analysis process. Several contemporary efforts consider CCF, however, most of these approaches introduce an exponential number of parameters and are computationally intensive because they require a complete characterization of the joint distribution of the components. As a result, these approaches are not scalable and cannot be applied to large systems. This paper presents an efficient approach to analyze system reliability considering CCF. The approach introduces only a quadratic number of parameters and is computationally efficient. The effectiveness of the approach is illustrated through a series of examples. The results indicate that the approach is both simple and efficient and can be applied to large systems.","PeriodicalId":403140,"journal":{"name":"2011 IEEE 13th International Symposium on High-Assurance Systems Engineering","volume":"41 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2011-11-10","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"124415289","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 9
期刊
2011 IEEE 13th International Symposium on High-Assurance Systems Engineering
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1