Questions of Interest …..
If the software's state is gradually corrupted over time,
- Transient failures
- When are output hazards first observed?
- How frequently?
- Mean-time-to-first-hazard?
- Hazard inter-arrival rates?
- What severity?
- What is a safe interval for resetting the system's state to the initial state? daily, monthly yearly? etc.
-
- Are there certain parts of the state that could benefit from "warning" probes?