The Community for Technology Leaders
Green Image
<p><b>Abstract</b>—The authors were recently involved in the development of a COBOL parser, specified formally in <it>Z</it>. The type of problem tackled was well suited to a formal language. The specification process was part of a life-cycle characterized by the front-loading of effort in the specification stage and the inclusion of a statistical testing stage. The specification was found to be error dense and difficult to comprehend. The <it>Z</it> was used to specify inappropriate procedural rather than declarative detail. Modularity and style problems in the <it>Z</it> specification made it difficult to review. In this sense, the application of formal methods was not successful. Despite these problems the estimated fault density for the product was 1.3 faults per KLOC, before delivery, which compares favorably with IBM's Cleanroom method. This was achieved, despite the low quality of the <it>Z</it> specification, through meticulous and effort-intensive reviews. However, because the faults were in critical locations, the reliability of the product was assessed to be unacceptably low. This demonstrates the necessity of assessing reliability as well as "correctness" during system testing. Overall, the experiences reported in this paper suggest a range of important lessons for anyone contemplating the practical application of formal methods.</p>
Formal methods, statistical testing, practical experience, reliability, fault density.
Martin Neil, Mark Southworth, Gary Ostrolenk, Mary Tobin, "Lessons from Using Z to Specify a Software Tool", IEEE Transactions on Software Engineering, vol. 24, no. , pp. 15-23, January 1998, doi:10.1109/32.663995
91 ms
(Ver )