11.07.2015 Views

BarrSlides_FINAL_SCRUBBED.pdf?utm_content=bufferb9206&utm_medium=social&utm_source=twitter

BarrSlides_FINAL_SCRUBBED.pdf?utm_content=bufferb9206&utm_medium=social&utm_source=twitter

BarrSlides_FINAL_SCRUBBED.pdf?utm_content=bufferb9206&utm_medium=social&utm_source=twitter

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

UNREASONABLE SINGLE POINTS OF FAILURESafety critical systems shouldn’t have single points of failure! This is the normal mode of design in automotive industryToyota tried to mitigate such risks, including in software! But missed some dangerous single points of failureFailed to prevent or contain faults …! There are single points of failure in the ETCSSome demonstrated in 2005 and 2008 Camry L4 vehiclesUnpredictable range of vehicle misbehaviors via task deathOther memory corruptions can be expected50Barr St. John Report

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!