Probabilities and failures Sample Clauses
Probabilities and failures. It appeared quite quickly that proving safety (or availability) properties without any failure is pointless, since in that case we can only prove that the system is safe...providing nothing wrong happens! It is therefore needed to model failures. But then, some proof obligations (safety properties after a failure) cannot be discharged any more. To prove these properties, it appeared that probabilities had to be added in the model. An experiment has been performed on the minipilot to add probabilities, with success.
