Inoculating software for survivability
A. K. Ghosh, Jeffrey M. Voas · Communications of the ACM · 1999
this paper, we are concerned with the survivability of the infrastructure to software flaws, anomalous events, and malicious attack. In the past, finding and removing software flaws has traditionally been the realm of software testing. Software testing has largely concerned itself with ensuring that software behaves correctly --- an intractable problem for any non-trivial piece of software. In this paper, we present "off-nominal" testing techniques that are not concerned with the correctness of the software, but with the survivability of the software in the face of anomalous events and malicious attack. Where software testing is focused on ensuring that the software computes the specified function correctly, we are concerned that the software continues to operate in the presence of unusual system events or malicious attacks. The off-nominal testing approach uses fault injection analysis to determine the effect of unusual or malicious attacks against software. Fault injection is the process of perturbing or corrupting a data state during program execution. Fault injection analysis is the process of determining the effect of that perturbation. The analysis may consist of simply measuring whether the perturbed state affected a particular output, or the analysis may determine whether system attributes such as safety, security, or survivability have been affected [12]. We describe two applications of fault injection analysis: one to improve the survivability of software before release and one to test the survivability of software once deployed in a fielded system. The former approach is aimed at software vendors to provide additional assurance prior to releasing the software (and after performing traditional testing) that the software has been exercised under unusual conditi...