Search NASASearch

Engineering topics

Kelly, J.

Publications and source records attributed to Kelly, J..

Reducing software security risk through an integrated approach

The fourth quarter delivery, FY'01 for this RTOP is a Property-Based Testing (PBT), 'Tester's Assistant' (TA). The TA tool is to be used to check compiled and pre-compiled code for potential security weaknesses that could be exploited by hackers. The TA Instrumenter, implemented mostly in C++ (with a small part in Java), parsels two types of files: Java and TASPEC. Security properties to be checked are written in TASPEC. The Instrumenter is used in conjunction with the Tester's Assistant Specification (TASpec)execution monitor to verify the security properties of a given program.

software security

Reducing Software Security Risk Through an Integrated Approach

This paper discusses new joint work by the California Institute of Technology's Jet Propulsion Laboratory and the University of California at Davis sponsored by the National Aeronautics and Space Administration to develop a security assessment instrument for the software development and maintenance life cycle.

risk matrix

2nd GSFC-JPL Quality Mission Workshop Report

The 2nd GSFC-JPL QMSW workshop brought together 56 participants mostly from GSFC and JPL to focus on critical challenges for mission software.

software infrastructure technology meterics practi

Prototype Tool Support for SEI Process and Risk Knowledge

We have developed a prototype of tool support for risk assessment that uses selected components of the Software Engineering Institute (SEI) information, specifically: Capability Maturity Model (CMM) process activities, CMM process goals and the SEI taxonomy of software project risks.

risk management risk assessment SEI CMM software r

Formal Inspection: A Tool for TQM

The goal of the Formal Inspection Program at the Jet Propulsion Laboratory (JPL) is to support projects wishing to use Formal Inspections to improve the quality of software and system level engineering products.

errors total quality

Results of a Formal Methods Demonstration Project

This paper describes the results of a cooperative study conducted by a team of researchers in formal methods at three NASA Centers to demonstrate FM techniques and to tailor them to critical NASA software systems. This pilot project applied FM to an existing critical software subsystem, the Shuttle's Jet Select subsystem (Phase I of an ongoing study). The present study shows that FM can be used successfully to uncover hidden issues in a highly critical and mature Functional Subsystem Software Requirements (FSSR) specification which are very difficult to discover by traditional means.

formal methods computer system specification compu

Formal Methods Demonstration Project for Space Applications

Requirements and design specifications are a high priority candidate for better software engineering techniques. Most hazardous software safety errors found during system integration and test of two NASA spacecraft were the result of requirements discrepancies or interface specifications. The highest density of major defects found through the use of software inspections was during the requirements phase. This was seven times higher than the density of major defects found in code inspections. Requirements errors are between 10 and 100 times more costly to fix at later phases of the software lifecycle than at the requirements phase itself. One study found that early lifecycle errors are the most likely to lead to catastrophic failures.

critical

Experience with a Technology Transfer Lifecycle and Implementation of Formal Inspections

In an organization with diverse project support and focus, a technology transfer program will be most successful with support from an advocate who can work to implement new technologies on multiple projects across organizational boundaries. In addition, a strong, ongoing technology transfer program needs to be in place to support training, implementation, metrics analysis, and project and organizational feedback of the new technology.

software technology transfer adoption support orga