Abstract. This paper describes recent work concerned with the speci cation of requirements on interactive systems and the de nition of user-level properties of such systems. A formal notation for describing and reasoning about the behaviour of systems and emergent properties is discussed, along with a technique that uses the formalism to investigate the resilience of systems to operator errors. These techniques are being used in the context of a project with British Aerospace the concepts are illustrated with a simple example from the area of aircraft warning systems.
Bob Fields, Peter C. Wright, Michael D. Harrison