Felicita Di Giandomenico

dblp:67/947 · DBLP profile ↗
← Back
53ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0002-8760-7299ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 17 · 2 first-author · 6 since 2021Security and privacy · 15 · 3 first-author · 2 since 2021Systems, architecture and hardware · 13 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 2 since 2021Computer networks · 4 · 1 since 2021Artificial intelligence and machine learning · 1
YearPublicationVenuePosition
2026 Using Metamorphic Relations in Redundancy-based Fault/Intrusion Tolerance
abstract
Redundancy is widely used as a method for fault and intrusion tolerance. However, if the redundant components lack sufficient diversity, potentially dangerous common mode failures may go undetected. To address this issue, the design diversity approach has been proposed in the literature for decades. In this article, we take an innovative approach to this problem by introducing a broader notion of diversity, which leverages Metamorphic Relations (MRs), i.e., necessary properties that must hold among diverse inputs and diverse outputs. We define two generic categories of MRs that establish data diversity and functional diversity. Furthermore, we elaborate on two corresponding logical architectures, paying particular attention to the necessary conditions for the adjudicator component. Finally, we present an initial evaluation of the proposed architectures, which points out the advantages with respect to their counterparts based on the traditional design diversity method, and discuss future research directions for this novel conceptual approach to redundancy-based fault/intrusion tolerance.
Felicita Di Giandomenico, Giulio Masetti, Francesca Lonetti, Antonia Bertolino
ACM Trans. Softw. Eng. Methodol.1
2025 Stochastic Modeling of Intrusion Tolerant Systems Based on Redundancy and Diversity
abstract
To cope with unforeseen attacks to software systems in critical application domains, redundancy-based ITSs schemes are among popular countermeasures to deploy. Designing the adequate ITS for the stated security requirements calls for stochastic analysis supports, able to assess the impact of variety of attack patterns on different ITS configurations. As contribution to this purpose, a stochastic model for ITS is proposed, whose novel aspects are the ability to account for both camouflaging components and for correlation aspects between the security failures affecting the diverse implementations of the software cyber protections adopted in the ITS. Extensive analyses are conducted to show the applicability of the model; the obtained results allow to understand the limits and strengths of selected ITS configurations when subject to attacks occurring in unfavorable conditions for the defender.
Silvano Chiaradonna, Felicita Di Giandomenico, Giulio Masetti
IEEE Trans. Computers2
2025 Quantitative Dependability Evaluation of Train Control Systems in Presence of Uncertainty: A Systematic Literature Review
abstract
Technological advances in modern Train Control Systems (TCSs) promise to improve dependability of railway transportation in terms of safety, availability, and capacity, notably by employing novel distancing policies such as Moving Block (MB) signaling and Virtual Coupling (VC), fueled by advanced train localization methods such as satellite positioning. At the same time, these technological advances raise notable concerns about the effects that uncertainty in critical TCS parameters (such as train position and speed) may have on dependability-related attributes. Recently, various approaches have been proposed to characterize such effects through quantitative measures, leveraging formal stochastic modeling and evaluation of the TCS behavior. In this paper, we illustrate the results of a systematic review of the literature on quantitative evaluation of dependability-related attributes of TCSs under uncertainty on vital parameters. Specifically, we have finally selected 42 relevant papers, published between 2011 and 2023, that succeed in giving, through an empirical perspective and classification, a comprehensive view of current research and practice in quantitative dependability assessment of TCSs.
Laura Carnevali, Felicita Di Giandomenico, Alessandro Fantechi, Stefania Gnesi, Gloria Gori
IEEE Trans. Intell. Transp. Syst.2
2024 An Integrated Perspective on the Evaluation of Complex Railway Systems
Davide Basile 0001, Maurice H. ter Beek, Laura Carnevali, Silvano Chiaradonna, Felicita Di Giandomenico, Alessandro Fantechi, Gloria Gori
ISoLA (5)5
2023 Cross-coverage testing of functionally equivalent programs
abstract
Cross-coverage of a program P refers to the test coverage measured over a different program Q that is functionally equivalent to P. The novel concept of cross-coverage can find useful applications in the test of redundant software. We apply here cross-coverage for test suite augmentation and show that additional test cases generated from the coverage of an equivalent program, referred to as cross tests, can increase the coverage of a program in more effective way than a random baseline. We also observe that -contrary to traditional coverage testing-cross coverage could help finding (artificially created) missing functionality faults.
Antonia Bertolino, Guglielmo De Angelis, Felicita Di Giandomenico, Francesca Lonetti
AST3
2023 Model-based security testing in IoT systems: A Rapid Review
abstract
Security testing is a challenging and effort-demanding task in IoT scenarios. The heterogeneous devices expose different vulnerabilities that can influence the methods and cost of security testing. Model-based security testing techniques support the systematic generation of test cases for the assessment of security requirements by leveraging the specifications of the IoT system model and of the attack templates. This paper aims to review the adoption of model-based security testing in the context of IoT, and then provides the first systematic and up-to-date comprehensive classification and analysis of research studies in this topic. We conducted a systematic literature review analysing 803 publications and finally selecting 17 primary studies, which satisfied our inclusion criteria and were classified according to a set of relevant analysis dimensions. We report the state-of-the-art about the used formalisms, the test techniques, the objectives, the target applications and domains; we also identify the targeted security attacks, and discuss the challenges, gaps and future research directions. Our review represents the first attempt to systematically analyze and classify existing studies on model-based security testing for IoT. According to the results, model-based security testing has been applied in core IoT domains. Models complexity and the need of modeling evolving scenarios that include heterogeneous open software and hardware components remain the most important shortcomings. Our study shows that model-based security testing of IoT applications is a promising research direction. The principal future research directions deal with: extending the existing modeling formalisms in order to capture all peculiarities and constraints of complex and large scale IoT networks; the definition of context-aware and dynamic evolution modelling approaches of IoT entities; and the combination of model-based testing techniques with other security test strategies such as penetration testing or learning techniques for model inference.
Francesca Lonetti, Antonia Bertolino, Felicita Di Giandomenico
Inf. Softw. Technol.3
2023 Implicit Reward Structures for Implicit Reliability Models
abstract
A new methodology for effective definition and efficient evaluation of dependability-related properties is proposed. The analysis targets the systems composed of a large number of components, each one modeled implicitly through high-level formalisms, such as stochastic Petri nets. Since the component models are implicit, the reward structure that characterizes the dependability properties has to be implicit as well. Therefore, we present a new formalism to specify those reward structures. The focus here is on component models that can be mapped to stochastic automata with one or several absorbing states so that the system model can be mapped to a stochastic automata network with one or several absorbing states. Correspondingly, the new reward structure defined on each component's model is mapped to a reward vector so that the dependability-related properties of the system are expressed through a newly introduced measure defined starting from those reward vectors. A simple, yet representative, case study is adopted to show the feasibility of the method.
Giulio Masetti, Leonardo Robol, Silvano Chiaradonna, Felicita Di Giandomenico
IEEE Trans. Reliab.4
2022 Solution Bundles of Markov Performability Models through Adaptive Cross Approximation
abstract
A technique to approximate solution bundles, i.e., solutions of a parametric model where parameters are treated as independent variables instead of constants, is presented for Markov models. Analyses based on an approximated solution bundle are more efficient than those that solve the model for all combinations of parameters’ values separately. In this paper the idea is to properly adapt low rank tensor approximation techniques, and in particular Adaptive Cross Approximation, to the evaluation of performability attributes. Application on exemplary case studies confirms the advantages of the new solution technique with respect to solving the model for all time and parameters’ combinations.
Giulio Masetti, Leonardo Robol, Silvano Chiaradonna, Felicita Di Giandomenico
DSN4
2022 Random Bad State Estimator to Address False Data Injection in Critical Infrastructures
abstract
Given their crucial role for a society and economy, an essential component of critical infrastructures is the Bad State Estimator (BSE), responsible for detecting malfunctions affecting elements of the physical infrastructure. In the past, the BSE has been conceived to mainly cope with accidental faults, under assumptions characterizing their occurrence. However, evolution of the addressed systems category consisting in pervasiveness of ICT-based control towards increasing smartness, paired with the openness of the operational environment, contributed to expose critical infrastructures to intentional attacks, e.g. exploited through False Data Injection (FDI). In the flow of studies focusing on enhancements of the traditional BSE to account for FDI attacks, this paper proposes a new solution that introduces randomness elements in the diagnosis process, to improve detection abilities and mitigate potentially catastrophic common-mode errors. Differently from existing alternatives, the strength of this new technique is that it does not require any additional components or alternative source of information with respect to the classic BSE. Numerical experiments conducted on two IEEE transmission grid tests, taken as representative use cases, show the applicability and benefits of the new solution.
Giulio Masetti, Silvano Chiaradonna, Leonardo Robol, Felicita Di Giandomenico
PRDC4
2021 Supervisory Synthesis of Configurable Behavioural Contracts with Modalities
Davide Basile 0001, Maurice H. ter Beek, Pierpaolo Degano, Axel Legay, Gian-Luigi Ferrari 0002, Stefania Gnesi, Felicita Di Giandomenico
FORTE7
2021 On identity-aware replication in stochastic modeling for simulation-based dependability analysis of large interconnected systems
Silvano Chiaradonna, Felicita Di Giandomenico, Giulio Masetti
Perform. Evaluation2
2020 30 Years of Simulation-Based Quantitative Analysis Tools: A Comparison Experiment Between Möbius and Uppaal SMC
Davide Basile 0001, Maurice H. ter Beek, Felicita Di Giandomenico, Alessandro Fantechi, Stefania Gnesi, Giorgio Oronzo Spagnolo
ISoLA (1)3
2020 Trading dependability and energy consumption in critical infrastructures: focus on the rail switch heating system
abstract
Traditionally, critical infrastructures demand for high dependability, being the services they provide essential to human beings and the society at large. However, more recent attention to cautious usage of energy resources is changing this vision and calls for solutions accounting for appropriate multi-requirements combinations when developing a critical infrastructure. In such a context, analysis supports able to assist the designer in envisioning a satisfactory trade-off among the multi-requirements for the system at hand are highly helpful. In this paper, the focus is on the railway sector and the contribution is a stochastic model-based analysis framework to quantitatively assess trade-offs between dependability indicators and electrical energy consumption incurred by the rail switch heating system.Moving from a preliminary study that concentrated on energy consumption only, the analysis framework has been extended to become a solid support to devise appropriate tuning of the heating policy that guarantees satisfactory trade-offs between dependability and energy consumption. An evaluation campaign in a variety of climate scenarios demonstrates the feasibility and utility of the developed framework.
Silvano Chiaradonna, Felicita Di Giandomenico, Giulio Masetti
PRDC2
2020 Failure management strategies for IoT-based railways systems
abstract
Railways monitoring and control are currently performed by different heterogeneous vertical systems working in isolation without or with limited cooperation among them. Such configuration, widely adopted in practical deployments today, is in contrast with the integrated vision of systems that are at the foundation of the smart-city concept. In order to overcome the current fractured ecosystem that monitors and controls railways functionalities, the adoption of a novel integrated approach is mandatory to create an all-in-one railway system. To this aim, new IoT-based communication technologies, like wireless or Power Line Communication technologies, are considered the main enablers to integrate in a very rapid and easy manner existing vertical systems. In this work, we analyse the architecture of future railways systems based on a mix of wireless and Power Line Communication technologies. In our analysis, we aim at studying possible failure management strategies on rail-road switches to improve the level of reliability, crucial requirement for systems that demand maximum resiliency as they manage a critical function of the infrastructure. In particular, we propose a set of solutions aimed at detecting and handling network and sensor failures to ensure continuity in the execution of the basic control functions. The proposed approach is evaluated by means of simulations and demonstrated to be effective in ensuring a good level of performance even when failures occur.
Francesca Righetti, Carlo Vallati, Giuseppe Anastasi, Giulio Masetti, Felicita Di Giandomenico
SMARTCOMP5
2020 Controller synthesis of service contracts with variability
abstract
Service contracts characterise the desired behavioural compliance of a composition of services. Compliance is typically defined by the fulfilment of all service requests through service offers, as dictated by a given Service-Level Agreement (SLA). Contract automata are a recently introduced formalism for specifying and composing service contracts. Based on the notion of synthesis of the most permissive controller from Supervisory Control Theory, a safe orchestration of contract automata can be computed that refines a composition into a compliant one. To model more fine-grained SLA and more adaptive service orchestrations, in this paper we endow contract automata with two orthogonal layers of variability: (i) at the structural level, constraints over service requests and offers define different configurations of a contract automaton, depending on which requests and offers are selected or discarded, and (ii) at the behavioural level, service requests of different levels of criticality can be declared, which induces the novel notion of semi-controllability. The synthesis of orchestrations is thus extended to respect both the structural and the behavioural variability constraints. Finally, we show how to efficiently compute the orchestration of all configurations from only a subset of these configurations. A prototypical tool supports the developed theory.
Davide Basile 0001, Maurice H. ter Beek, Pierpaolo Degano, Axel Legay, Gian-Luigi Ferrari 0002, Stefania Gnesi, Felicita Di Giandomenico
Sci. Comput. Program.7
2019 Stochastic Evaluation of Large Interdependent Composed Models Through Kronecker Algebra and Exponential Sums
Giulio Masetti, Leonardo Robol, Silvano Chiaradonna, Felicita Di Giandomenico
Petri Nets4
2018 Supporting CPS Modeling Through a New Method for Solving Complex Non-holomorphic Equations
abstract
Modeling cyber-physical systems (CPSs) for assessment or design support purposes is a complex activity. Capturing all relevant physical, structural or behavioral aspects of the system at hand is a crucial task, which often implies representation of peculiar features/constraints through non-linear equations. Values that fulfill the constraints, described with a domain specific language, are obtained solving the equations through a properly developed solution tool. Only for a limited set of CPSs it is possible to find a straightforward strategy to design the software that solves the constraints equations. In the general case, instead, the modeler has to develop an ad-hoc artifact for each different system. This is the case of non-holomorphic but real analytic complex equations, adopted to represent system components with wave behaviors. In this paper, we present a new approach to develop a software for solving such complex equations following a generative programming strategy, based on Wirtinger derivatives within the Newton-Raphson method.
Giulio Masetti, Simone Dutto, Silvano Chiaradonna, Felicita Di Giandomenico
MODELSWARD4
2018 A tour of secure software engineering solutions for connected vehicles
Antonia Bertolino, Antonello Calabrò, Felicita Di Giandomenico, Giuseppe Lami, Francesca Lonetti, Eda Marchetti, Fabio Martinelli, Ilaria Matteucci, Paolo Mori
Softw. Qual. J.3
2017 A Stochastic Modeling Approach for an Efficient Dependability Evaluation of Large Systems with Non-anonymous Interconnected Components
abstract
This paper addresses the generation of stochastic models for dependability and performability analysis of complex systems, through automatic replication of template models. The proposed solution is tailored to systems composed by large populations of similar non-anonymous components, interconnected with each other according to a variety of topologies. A new efficient replication technique is presented and its implementation is discussed. The goal is to improve the performance of simulation solvers with respect to standard approaches, when employed in the modeling of the addressed class of systems, in particular for loosely interconnected system components (as typically encountered in the electrical or transportation sectors). Effectiveness of the new technique is demonstrated by comparison with a state of the art alternative solution on a representative case study.
Giulio Masetti, Silvano Chiaradonna, Felicita Di Giandomenico
ISSRE3
2017 Enhancing Models Correctness through Formal Verification: A Case Study from the Railway Domain
abstract
Model-based approaches are widely used for analysing systems belonging to a variety of domains, including the transportation sector. A critical issue with models is their validation, in order to justifiably put reliance on the analysis results they provide (including non functional indicators such as reliability, performance and energy consumption). Typically, cross-validation is performed, e.g. through exercising modelling by different formalisms/tools or through forms of experimental analysis. In this paper, we address validation of a case study from the railway domain via formal techniques, specifically with automata-based models. Validation of interaction aspects of Stochastic Activity Networks models of rail road switch heaters, developed for the purpose of evaluating energy consumption and reliability indicators, is performed through a tool based on contract automata, a recently introduced formalism for verifying properties of communication-based applications.
Davide Basile 0001, Felicita Di Giandomenico, Stefania Gnesi
MODELSWARD2
2016 Tuning Energy Consumption Strategies in the Railway Domain: A Model-Based Approach
Davide Basile 0001, Felicita Di Giandomenico, Stefania Gnesi
ISoLA (2)2
2016 Achieving functional and non functional interoperability through synthesized connectors
Nicola Nostro, Romina Spalazzese, Felicita Di Giandomenico, Paola Inverardi
J. Syst. Softw.3
2011 Modeling and analysis of the impact of failures in Electric Power Systems organized in interconnected regions
abstract
Analysis of interdependencies in Electric Power Systems (EPS) has been recognized as a crucial and challenging issue to improve their trustworthiness. The recent liberalization process in energy markets has promoted the entry of a variety of operators in the electricity industry. The resulting new organization contributed to increase in complexity, heterogeneity and interconnection. This paper proposes a framework for analyzing EPS organized as a set of interconnected regions, both from the point of view of the electric power grid and of the cyber control infrastructure. The emphasis is on interdependencies and in assessing their impact on indicators representative of the QoS perceived by users. Taking a reference power grid as test case, the effects of failures on selected measures are shown, both in case the grid is partitioned in a number of regions and in case of a single region, to illustrate the behavior of different grid and control configurations.
Silvano Chiaradonna, Felicita Di Giandomenico, Nicola Nostro
DSN2
2011 Automated Refinement of Dependability Analysis through Monitoring in Dynamically Connected Systems
abstract
Model-based analysis is a well-established method to assess the dependability of a system before deployment. It is well known that, in highly dynamic contexts, the accuracy of the analysis results can be limited because unpredictable phenomena may affect the system during its operation. In such contexts, the analysis typically needs to be refined with data obtained from real system executions. In this paper we tackle the issue of refining model-based dependability analysis in automated systems through monitoring. Specifically, we report on our preliminary results on the development of a system that exploits the synergic use of an automated approach for model-based dependability analysis and a flexible monitoring architecture.
Antonia Bertolino, Antonello Calabrò, Felicita Di Giandomenico, Marco Martinucci, Paolo Masci 0001
ISADS3
2011 Towards Automated Dependability Analysis of Dynamically Connected Systems
abstract
Dynamic environments may include autonomous and decentralised components that pose many challenges from the point of view of interoperability, thus triggering research studies in several directions. One recent research direction explores the automatic composition of heterogeneous systems through connectors synthesised at run-time. Besides functional properties, such connectors generally need to satisfy also non-functional (dependability-related) properties. This paper investigates the definition of an automated procedure to support the synthesis of dependable connectors.
Paolo Masci 0001, Marco Martinucci, Felicita Di Giandomenico
ISADS3
2010 Dependability Analysis and Verification for Connected Systems
Felicita Di Giandomenico, Marta Z. Kwiatkowska, Marco Martinucci, Paolo Masci 0001, Hongyang Qu 0001
ISoLA (2)1
2009 A Decomposition-Based Modeling Framework for Complex Systems
abstract
Stochastic model-based approaches are widely used for performability evaluation of complex software/hardware systems. Many techniques have been developed to mitigate the complexity of the associated models, but most of them are domain-specific, and they support the analysis of a limited class of systems. This paper provides a contribution in the definition of a general modeling framework that adopts three different types of decomposition techniques to deal with model complexity.
Paolo Lollini, Andrea Bondavalli, Felicita Di Giandomenico
IEEE Trans. Reliab.3
2008 Interdependency Analysis in Electric Power Systems
Silvano Chiaradonna, Felicita Di Giandomenico, Paolo Lollini
CRITIS2
2007 On a Modeling Framework for the Analysis of Interdependencies in Electric Power Systems
abstract
Nowadays, economy, security and quality of life heavily depend on the resiliency of a number of critical infrastructures, including the electric power system (EPS), through which vital services are provided. In existing EPS two cooperating infrastructures are involved: the electric infrastructure (EI) for the electricity generation and transportation to final users, and its information-technology based control system (ITCS) devoted to controlling and regulating the EI physical parameters and triggering reconfigurations in emergency situations. This paper proposes a modeling framework to capture EI and ITCS aspects, focusing on their interdependencies that contributed to the occurrence of several cascading failures in the past 40 years. A quite detailed analysis of the EI and ITCS structure and behavior is performed; in particular, the ITCS and EI behaviors are described by discrete and hybrid-state processes, respectively. To substantiate the approach, the implementation of a few basic modeling mechanisms inside an existing multiformalism/ multi-solution tool is also discussed.
Silvano Chiaradonna, Paolo Lollini, Felicita Di Giandomenico
DSN3
2007 Workshop on Architecting Dependable Systems (WADS 2007)
abstract
This workshop summary gives a brief overview of the workshop on "Architecting Dependable Systems" held in conjunction with DSN 2007. The main aim of this workshop is to promote cross-fertilization between the software architecture and dependability communities. We believe that both of them will benefit from clarifying approaches that have been previously tested and have succeeded as well as those that have been tried but have not yet been shown to be successful.
Rogério de Lemos, Felicita Di Giandomenico, Cristina Gacek
DSN2
2006 Hidden Markov Models as a Support for Diagnosis: Formalization of the Problem and Synthesis of the Solution
abstract
In modern information infrastructures, diagnosis must be able to assess the status or the extent of the damage of individual components. Traditional one-shot diagnosis is not adequate, but streams of data on component behavior need to be collected and filtered over time as done by some existing heuristics. This paper proposes instead a general framework and a formalism to model such over-time diagnosis scenarios, and to find appropriate solutions. As such, it is very beneficial to system designers to support design choices. Taking advantage of the characteristics of the hidden Markov models formalism, widely used in pattern recognition, the paper proposes a formalization of the diagnosis process, addressing the complete chain constituted by monitored component, deviation detection and state diagnosis. Hidden Markov models are well suited to represent problems where the internal state of a certain entity is not known and can only be inferred from external observations of what this entity emits. Such over-time diagnosis is a first class representative of this category of problems. The accuracy of diagnosis carried out through the proposed formalization is then discussed, as well as how to concretely use it to perform state diagnosis and allow direct comparison of alternative solutions
Alessandro Daidone, Felicita Di Giandomenico, Andrea Bondavalli, Silvano Chiaradonna
SRDS2
2004 Fast Abstracts
Felicita Di Giandomenico
DSN1
2004 Congestion analysis during outage, congestion treatment and outage recovery for simple GPRS networks
abstract
This paper deals with congestion analysis of a simple GPRS network composed by two cells partially overlapping. In particular, we consider that one of the two cells is affected by an outage and we analyze the effectiveness of applying a class of congestion treatment techniques that ultimately results in a switching of users from the congested cell to the other one. For this purpose, we introduce a modelling technique to support a proper calibration of the parameters involved in a reconfiguration action, in order to successfully treat the congestion phenomenon. The effectiveness of a reconfiguration action is evaluated in terms of indicators that represent the quality of service (QoS) perceived by the users in the congested and adjacent cells.
Paolo Lollini, Andrea Bondavalli, Felicita Di Giandomenico, Stefano Porcarelli
ISCC3
2004 Dependability modeling and evaluation of multiple-phased systems using DEEM
abstract
Multiple-Phased Systems (MPS), i.e., systems whose operational life can be partitioned in a set of disjoint periods, called "phases", include several classes of systems such as Phased Mission Systems and Scheduled Maintenance Systems. Because of their deployment in critical applications, the dependability modeling and analysis of Multiple-Phased Systems is a task of primary relevance. The phased behavior makes the analysis of Multiple-Phased Systems extremely complex. This paper describes the modeling methodology and the solution procedure implemented in DEEM, a dependability modeling and evaluation tool specifically tailored for Multiple Phased Systems. It also describes its use for the solution of representative MPS problems. DEEM relies upon Deterministic and Stochastic Petri Nets as the modeling formalism, and on Markov Regenerative Processes for the model solution. When compared to existing general-purpose tools based on similar formalisms, DEEM offers advantages on both the modeling side (sub-models neatly model the phase-dependent behaviors of MPS), and on the evaluation side (a specialized algorithm allows a considerable reduction of the solution cost and time). Thus, DEEM is able to deal with all the scenarios of MPS which have been analytically treated in the literature, at a cost which is comparable with that of the cheapest ones, completely solving the issues posed by the phased-behavior of MPS.
Andrea Bondavalli, Silvano Chiaradonna, Felicita Di Giandomenico, Ivan Mura
IEEE Trans. Reliab.3
2003 Service-Level Availability Estimation of GPRS
abstract
The General Packet Radio Service (GPRS) extends the Global System Mobile Communication (GSM) by introducing a packet-switched transmission service. This paper analyzes the GPRS behavior under critical conditions. In particular, we focus on outages, which significantly impact the GPRS dependability. In fact, during outage periods, the cumulative number of users trying to access the service grows proportionally over time. When the system resumes its operations, the overload caused by accumulated users determines a higher probability of collisions on resources assignment and, therefore, a degradation of the overall QoS. This paper adopts a stochastic activity network modeling approach for evaluating the dependability of a GPRS network under outage conditions. The major contribution of this study lies in the novel perspective the dependability study is framed in. Starting from a quite classical availability analysis, the network dependability figures are incorporated into a very detailed service model that is used to analyze the overload effect GPRS has to face after outages, gaining deep insights on its impact on user's perceived QoS. The result of this modeling is an enhanced availability analysis, which takes into account not only the bare estimation of unavailability periods, but also the important congestion phenomenon following outages that contribute to service degradation for a certain period of time after operations resume.
Stefano Porcarelli, Felicita Di Giandomenico, Andrea Bondavalli, Massimo Barbera, Ivan Mura
IEEE Trans. Mob. Comput.2
2002 Analyzing quality of service of GPRS network systems from a user's perspective
abstract
With reference to the General Packet Radio Service (GPRS), an extension of the Global System for Mobile Communication (GSM) addressing packet-oriented traffic, this paper contributes to the analysis of the service accomplishment level perceived by GPRS users. The proposed modeling approach builds separately the GPRS and user models; the focus is on the GPRS random access procedure on the one side, and different classes of user behavior on the other side. The overall model is composed of the basic submodels. Quantitative analysis, performed using a simulation approach, is carried out, showing the impact of users' characteristics and network load on identified indicators expressing the QoS as perceived by users.
Stefano Porcarelli, Felicita Di Giandomenico, Andrea Bondavalli
ISCC2
2002 An adaptive approach to achieving hardware and software fault tolerance in a distributed computing environment
Andrea Bondavalli, Silvano Chiaradonna, Felicita Di Giandomenico
J. Syst. Archit.3
2001 Analysis of the Effects of Outages on the Quality of Service of GPRS Network Systems
abstract
The General Packet Radio Service (GPRS) extends the Global System Mobile Communications (GSM) by addressing packet-oriented traffic. Availability is the most important dependability requirement for such communication systems as GPRS. Focusing on the contention phase, where users compete for channel reservation, this paper analyses the GPRS with the objective to understand its behaviour under critical conditions, as determined by periods of outages, which significantly impact on the resulting dependability. In fact, during outages (service unavailability), users trying to access the service accumulate, leading to an overload of the system. When the system resumes its operations, the accumulated users determine a higher probability of collisions on resources assignment (and therefore a degradation of the QoS perceived by the users). Our analysis, performed using a simulation approach, allowed us to gain insights on the impact of outages on the QoS and of the overload that GPRS systems have to face after outages.
F. Tataranni, Stefano Porcarelli, Felicita Di Giandomenico, Andrea Bondavalli
DSN3
2001 Analysis and Estimation of the Quality of Service of Group Communication Protocols
abstract
QoS (defined as a proper set of quantitative characteristics) analysis is a necessary step for the early verification and validation of an appropriate design, and for taking design decisions about the most rewarding choice, in relation to user requirements. We describe an analytical approach for the evaluation of the QoS offered by a family of group communication protocols in a wireless environment, and use experimental data to feed our models. Specific indicators have been defined and evaluated, which capture the main characteristics of the protocols and of the environment, focusing our attention on performance and dependability attributes. The defined models account for the correlation among successive packet transmissions due to fading and user mobility. The main purpose of our analysis is to provide a fast, cost effective, and formally sound way to further analyze and understand the protocol behavior and its environment.
Andrea Coccoli, Andrea Bondavalli, Felicita Di Giandomenico
ISORC3
2001 Tuning of Database Audits to Improve Scheduled Maintenance in Communication Systems
Stefano Porcarelli, Felicita Di Giandomenico, Amine Chohra, Andrea Bondavalli
SAFECOMP2
2001 Evaluation of Fault-Tolerant Multiprocessor Systems for High Assurance Applications
abstract
In designing high assurance systems, the dependability goals are achieved through the adoption of several fault-tolerance techniques. Unfortunately, their combined effect on the system cannot be, in the general case, derived by straightforward composition of the stand-alone component's analysis, because of mutual dependence of their controlling parameters. In this paper the assessment of overall system dependability induced by such integrated fault-tolerance organization is carried out through a stochastic simulation approach. To this purpose, a few fault-tolerant multiprocessor architectures, based on the integrated usage of standard error-processing structures with a recently-proposed diagnostic mechanism, called $\alpha$-count, are selected and evaluated. The diagnostic mechanism gets its input (error signals) from the error-processing mechanism, whose behaviour is in turn influenced by the rapidity and correctness with which $\alpha$-count identifies permanently/intermittently faulty processors. The choice of the basic fault-tolerance mechanisms to adopt, as well as the reference-system architecture, has been driven by the characteristics of the envisaged target applications: mainly, stringent dependability requirements, to be traded with adequate levels of performance and cost. The analysis has focused on performability, which is an appropriate measure to evaluate whether a certain design is ‘better’ than another under dependability and performance point of view.
Fabrizio Grandoni 0002, Silvano Chiaradonna, Felicita Di Giandomenico, Andrea Bondavalli
Comput. J.3
2000 A Position on Design, Methods, and Tools for Object-Oriented Real-Time Computing
abstract
Real-time is a major characteristic of many systems, increasingly employed today in disparate sectors of our society. To specify and program systems, exhibiting real-time properties, a number of computing paradigms have been adopted, both explicitly defined to specify real-time behaviours and imported from other application areas with the addition of mechanisms to deal with real-time. The paper discusses object oriented real-time system design and tools.
Andrea Bondavalli, Felicita Di Giandomenico
ISORC2
2000 Scheduling Solutions for Supporting Dependable Real-Time Applications
abstract
This paper deals with tolerance to timing faults in time-constrained systems. TAFT (Time Aware Fault-Tolerant) is a recently devised approach which applies tolerance to timing violations. According to TAFT, a task is structured in a pair, to guarantee that deadlines are met (although possibly offering a degraded service) without requiring the knowledge of task attributes difficult to estimate in practice. Wide margin of actions is left by the TAFT approach in scheduling the task pairs, leading to disparate performances; up to now, poor attention has been devoted to analyse this aspect. The goal of this work is to investigate on the most appropriate scheduling policies to adopt in a system structured in the TAFT fashion, in accordance with system conditions and application requirements. To this end, all experimental evaluation will be conducted based on a variety of scheduling policies, to derive useful indications for the system designer about the most rewarding policies to apply.
F. Sandrini, Felicita Di Giandomenico, Andrea Bondavalli, Edgar Nett
ISORC2
2000 The meaning and role of value in scheduling flexible real-time systems
Alan Burns 0001, Divya Prasad, Andrea Bondavalli, Felicita Di Giandomenico, Krithi Ramamritham, John A. Stankovic, Lorenzo Strigini
J. Syst. Archit.4
2000 Threshold-Based Mechanisms to Discriminate Transient from Intermittent Faults
abstract
This paper presents a class of count-and-threshold mechanisms, collectively named /spl alpha/-count, which are able to discriminate between transient faults and intermittent faults in computing systems. For many years, commercial systems have been using transient fault discrimination via threshold-based techniques. We aim to contribute to the utility of count-and-threshold schemes, by exploring their effects on the system. We adopt a mathematically defined structure, which is simple enough to analyze by standard tools. /spl alpha/-count is equipped with internal parameters that can be tuned to suit environmental variables (such as transient fault rate, intermittent fault occurrence patterns). We carried out an extensive behavior analysis for two versions of the count-and-threshold scheme, assuming, first, exponentially distributed fault occurrencies and, then, more realistic fault patterns.
Andrea Bondavalli, Silvano Chiaradonna, Felicita Di Giandomenico, Fabrizio Grandoni 0002
IEEE Trans. Computers3
1999 An Optimal Value-Based Admission Policy and its Reflective Use in Real-Time Systems
Andrea Bondavalli, Felicita Di Giandomenico, Ivan Mura
Real Time Syst.2
1999 A Contribution to the Evaluation of the Reliability of Iterative-Execution Software
abstract
This paper deals with the reliability of software executed iteratively, as for example in process control applications. The probability of mission survival is evaluated taking account of two characteristics of iterative software: (a) system failure, defined in terms of the behaviour of the software over successive iterations, because the controlled system can usually tolerate short bursts of errors; (b) the probabilistic correlation between successive executions of the software, which is to be expected for various reasons. The paper presents models accounting for these characteristics and evaluates their effects. The interesting case of fault-tolerant software is considered as well. Using the example of a ‘pair-and-spare’ type fault-tolerant scheme, the relationships between different aspects of failure behaviour that are covered by the models developed here, and those used elsewhere for fault-tolerant software, are shown. Copyright © 1999 John Wiley & Sons, Ltd.
Andrea Bondavalli, Silvano Chiaradonna, Felicita Di Giandomenico, Lorenzo Strigini
Softw. Test. Verification Reliab.3
1998 State Restoration in a COTS-Based N-Modular Architecture
abstract
Mechanisms for restoring the state of a channel in an N-modular redundant architecture are necessary to prevent redundancy attrition due to transient faults and to allow failed channels to be brought back on line after repair. This paper considers software-implemented mechanisms for state restoration (SR) in a generic fault-tolerant architecture in which both the underlying hardware and operating system are commercial off-the-shelf (COTS) components. State restoration involves copying the values of state variables from the active channel(s) across to the joining channel. Concurrent updating of state variables by application tasks is considered. Two state restoration schemes are considered: Running SR and Recursive SR. In the former, each state variable is copied exactly once while concurrent updates are written through to the joining channel. In the latter state variables are copied once and then recopied recursively until no concurrent updates are detected.
Andrea Bondavalli, Felicita Di Giandomenico, Fabrizio Grandoni 0002, David Powell, Christophe Rabéjac
ISORC2
1995 Dependability of Iterative Software: A Model for Evaluating the Effects of Input Correlation
Andrea Bondavalli, Silvano Chiaradonna, Felicita Di Giandomenico, S. La Torre
SAFECOMP3
1994 Efficient Fault Tolerance: An Approach to Deal with Transient Faults in Multiprocessor Architectures
abstract
Dynamic error processing approaches are an important mechanism to increase the reliability in a multiprocessor system, while making efficient use of the available resources. To this end, dynamic error processing must be integrated with a fault treatment approach aiming at optimising resource utilisation. In this paper we propose a diagnosis approach that, accounting for transient faults, tries to remove units very cautiously and to balance between two conflicting requirements. The first is to avoid the removal of units that have experienced transient faults and can be still useful for the system and the other is to avoid to keep failed units whose usage may lead to a premature failure of the system. The proposed fault treatment approach is integrated with a mechanism for dynamic error processing in a complete fault tolerance strategy. Reliability analyses based on the Markov approach and an efficiency evaluation performed by simulation are carried out.
Andrea Bondavalli, Silvano Chiaradonna, Felicita Di Giandomenico
ICPADS3
1991 Flexible Schemes for Application-Level Fault Tolerance
abstract
It is pointed out that the design of fault-tolerance provisions in the application level is normally necessary, but difficult and error-prone due to its ad-hoc nature. Structuring schemes have been proposed to reduce the difficulty of this task, but they appear too restrictive for the building of large, heterogeneous applications. The redundant structures that can be used in the individual components of a system depend on their requirements or inherent characteristics; it would be useful to combine components using different basic schemes. As an example, the authors propose a solution for interfacing components using conversations for backward recovery with components using atomic transactions. Constraints for the designers of the components to be interfaced and requirements on the virtual machine supporting their execution are defined. Ways a classification of components could be organized to allow the formulation of more general solutions are discussed.>
Lorenzo Strigini, Felicita Di Giandomenico
SRDS2
1990 Adjudicators for Diverse-Redundant Components
abstract
The authors define the adjudication problem, summarize the existing literature on the topic, and investigate the use of probabilistic knowledge about error/faults in the subcomponents of a fault-tolerant component to obtain good adjudication functions. They prove the existence of an optimal adjudication function, which is useful both as an upper bound on the probability of correctly adjudged obtainable output and as a guide for design decisions.>
Felicita Di Giandomenico, Lorenzo Strigini
SRDS1
1987 A Gracefully Degradable Algorithm for Byzantine Agreement
Felicita Di Giandomenico, M. L. Guidotti, Fabrizio Grandoni 0002, Luca Simoncini
SRDS1