首页> 外文会议>Integrated Communications, Navigation and Surveillance Conference >Anatomy of a No-Equipment-Failed (NEF) ICNS system malfunction: The case of Singapore Airlines SQ-327 Runway Excursion
【24h】

Anatomy of a No-Equipment-Failed (NEF) ICNS system malfunction: The case of Singapore Airlines SQ-327 Runway Excursion

机译:无设备故障(NEF)ICNS系统故障的解剖:以新加坡航空SQ-327跑道游览为例

获取原文

摘要

Complex systems-of-systems are characterized by emergent behavior resulting from the interaction of behaviorally complex, distributed, autonomous sub-systems or agents. Although the individual subsystems (e.g. Instrument Landing System, aircraft) are certified to high levels of reliability (e.g. 10-7), the interactions between the sub-systems is typically not explicitly, exhaustively, tested or certified. As a consequence, there can emerge scenarios in which a sub-system can find itself commanded into unsafe operating regimes without a failure of any sub-system or agent.This paper describes a No Equipment Failed Malfunction (NEFM) analysis of the Singapore Airlines SQ-327 runway excursion that occurred November 3, 2011 at Munich airport. In the sequence of events of the incident, all the equipment operated as designed (i.e. no equipment failed) and the operators each performed according to their approved Standard Operating Procedures. The analysis highlights: (1) the need for comprehensive testing of the interaction between agents that can lead to scenarios resulting in rare hazardous outcomes, and (2) the vulnerability of designing human operators to monitor these complex system interactions and respond in a timely and appropriate manner. The need for comprehensive system-of-system sequential scenario testing, including exhaustive combinatorics using super computers, and the need for crowd-sourcing through voluntary reporting and safety management systems to address these issues is discussed.
机译:复杂的系统系统的特征是出现的行为,这些行为是由行为复杂的,分布式的,自治的子系统或代理的交互产生的。尽管各个子系统(例如仪表着陆系统,飞机)均已获得高可靠性级别(例如10-7)的认证,但子系统之间的交互通常并未经过明确,详尽,测试或认证。结果,可能会出现这样的情况:子系统可以发现自己被命令进入不安全的操作状态,而没有任何子系统或代理发生故障。本文介绍了新加坡航空公司SQ的无设备故障(NEFM)分析。 -327发生于2011年11月3日在慕尼黑机场发生的跑道偏移。在发生事件的顺序中,所有设备均按设计运行(即没有设备发生故障),操作员均按照其批准的标准操作程序进行操作。分析强调:(1)需要全面测试代理之间的交互,这可能导致导致罕见的危险结果的场景;(2)设计人员以监控这些复杂的系统交互并及时做出响应的脆弱性适当的方式。讨论了对全面的系统级顺序场景测试的需求,包括使用超级计算机进行详尽的组合测试,以及通过自愿报告和安全管理系统进行众包以解决这些问题的需求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号