Source-linked AI summary
Large-scale Complex IT Systems
Ian Sommerville, Dave Cliff, Radu Calinescu, Justin Keen, Tim Kelly, Marta Kwiatkowska, John McDermid, Richard Paige
TL;DR
Large-scale IT systems increasingly integrate independently managed software systems, creating complexity that current software engineering cannot adequately control. The paper explains why inherent complexity prevents current methods from scaling and proposes a research and education agenda. It concludes that incremental improvements are insufficient and that different engineering approaches are needed to construct trustworthy complex systems.
Problem
Current software engineering cannot effectively manage the inherent complexity of large-scale coalitions of independently managed systems.
Method
The paper analyzes the limits of reductionist software engineering and proposes research, education, dynamic modeling, simulation, and empirical study agendas.
Results
The paper concludes that existing software engineering approaches cannot be scaled up to create coalitions of systems and that incremental improvements are insufficient.
Takeaways & Limitations
Software engineering must address the systems, people, organizations, and operational environments surrounding software-intensive coalitions.
Takeaways & Limitations
Research is constrained by insufficient knowledge of what happens in real coalitions, requiring long-term empirical studies of their systems and development processes.
Abstract
from arXiv · showhide
This paper explores the issues around the construction of large-scale complex systems which are built as 'systems of systems' and suggests that there are fundamental reasons, derived from the inherent complexity in these systems, why our current software engineering methods and techniques cannot be scaled up to cope with the engineering challenges of constructing such systems. It then goes on to propose a research and education agenda for software engineering that identifies the major challenges and issues in the development of large-scale complex, software-intensive systems. Central to this is the notion that we cannot separate software from the socio-technical environment in which it is used.
1. Introduction
The paper uses the 2010 Flash Crash to illustrate how interactions among independently managed software systems can produce large-scale socio-technical failures. It argues that growing dependence on such complex systems requires new software engineering techniques and an expanded research and education agenda.
- In about 10 minutes, the Dow Jones Industrial Average fell over 600 points, erasing around $800bn in market value.
- The crash reversed within minutes, with most losses recovered and share prices returning close to pre-crash levels.
- A CFTC and SEC investigation attributed the trigger to a single urgent $4.1bn futures-contract sale interacting with rapidly trading algorithms.
- The Flash Crash was not caused by software bugs but by unforeseen interactions among independently managed systems, producing failure in the broader socio-technical market.
- Because society increasingly depends on integrated complex IT systems, the paper calls for new engineering techniques and a research and education agenda.
2. Coalitions of systems
The paper distinguishes its “coalition of systems” from centrally controlled systems of systems: coalitions emerge through interaction among independently managed systems with potentially conflicting interests. This lack of common authority makes dependability and behavior difficult to control.
- Large complex IT systems are assembled from existing and new systems that remain independently controlled and managed.
- A conventional system of systems may integrate independent systems under one organization that owns the whole system and can influence its components.
- The paper calls an emergent, mutually beneficial collection of interacting systems a “coalition of systems,” replacing the term “virtual system of systems.”
- Coalition members may cooperate reluctantly, compete or behave hostilely, and enter or leave according to their perceived interests.
- Coalition engineering cannot impose overall dependability because no central authority controls constituent behavior, replacement, or organizational continuity.
- Coalitions resemble wicked systems because they continually change during development and use and cannot be completely understood.
3. IT System complexity
The paper separates complexity caused by changing relationships from complexity caused by limited knowledge. It argues that this distinction explains why new software engineering approaches are needed for large coalitions of systems.
- With few, slowly changing relationships, deterministic models can support prediction of system properties.
- Many dynamic relationships make systems non-deterministic, with characteristics emerging through use and changing with the external environment.
- Trust illustrates dynamic relationships because failures can reduce trust and trigger more stringent checks between components.
- Inherent complexity depends on changing relationships and cannot be analyzed fully during development because it depends on the operating environment.
- Epistemic complexity arises from insufficient knowledge of system elements and relationships, even when those relationships are relatively static.
- Epistemic complexity increases with system size, making behavior and properties harder to understand and predict.
- The distinction between inherent and epistemic complexity is presented as the primary reason new software engineering approaches are required.
4. Reductionism and software engineering
The paper argues that reductionist software engineering works best when one organization controls a system, but fails to scale to coalitions with inherent complexity. It therefore calls for engineering that includes surrounding systems, people, organizations, and operational environments.
- Software engineering is effective when inherent complexity is low and one organization controls all system elements, but inadequate for highly complex coalitions.
- The paper identifies a fundamental mismatch between current software engineering and the inherent complexity of 21st-century wicked systems.
- Reductionism treats a complex system as the sum of its parts, encouraging discrete components, defined interfaces, and subsequent integration.
- Software engineering research has emphasized decomposition, component construction, and system integration as ways to apply this reductionist view.
- A core reductionist assumption is that system owners control development and can enforce decisions about component interactions.
- Wicked systems violate assumptions of rational technical decisions, clear problems, and stable system boundaries because organizational politics and stakeholder perspectives reshape them.
- Software engineering should examine the wider socio-technical environment and model or simulate operational contexts to manage coalition relationships.
5. Challenges for research and education
The paper argues that large-scale coalitions of independently managed systems require interdisciplinary research beyond incremental improvements to current software engineering. Its agenda addresses modelling, monitoring, recovery, socio-technical integration, self-management, configuration, agility, certification, and probabilistic verification.
- Research agenda: Large-scale complex systems require interdisciplinary research, while incremental improvements to existing software engineering techniques will be insufficient.The agenda must also address immediate practical problems because such systems are already being engineered.
- Research agenda: Coalitions of systems require engineering both individual systems for coalition participation and the coalition’s orchestration and configuration for organizational needs.This framing defines the paper’s proposed top-10 research problems.
- Modelling and monitoring: Dynamic models updated with real-time system information are needed for rapid what-if assessments of system changes, while simulations cannot predict every possible problem.The proposed models should adapt performance and failure representations automatically from monitoring data.
- Modelling and monitoring: Coalitions need monitoring indicators that provide early warnings of instability and support switching to safe-mode operation when necessary.The Flash Crash is cited as a case where such indicators were absent before the system became unstable.
- Recovery and socio-technical systems: Because failure may be ambiguous and independently managed systems cannot reliably avoid it, human operators may need to intervene in recovery.The paper therefore treats designing for failure as distinct from relying only on fault avoidance, detection, and tolerance.
- Research agenda: The agenda includes socio-technical methods, self-management, dynamic configuration, agile multi-organization development, incremental certification, and probabilistic verification.Probabilistic verification asks about the probability of satisfying essential properties under probabilistic, real-time, and non-deterministic behavior.
10. How should shared knowledge in a coalition of systems be represented?
Shared knowledge in dynamic coalitions must address the meaning of exchanged information rather than merely its technical compatibility. The paper also connects this challenge to empirical research, practical socio-technical techniques, and multidisciplinary education for complex systems engineers.
- Shared knowledge representation: Service interfaces and standards-based representations may provide compatibility, but dynamic coalitions still need systems to share the meaning of exchanged information.The paper identifies ontologies as one possible way to represent shared meaning when systems enter or leave the coalition.
- Evidence and practice: Research on coalitions is constrained by limited knowledge of how real systems, developers, and operators handle practical problems.The paper calls for long-term empirical studies to inform new ideas, tools, and methods.
- Evidence and practice: The LSCITS project works with industry, financial-services, and healthcare partners to understand systems-engineering problems, including external access to large healthcare datasets.This engagement provides a practical setting for studying coalitions of systems.
- Practical techniques: The project develops socio-technical engineering, designing-for-failure, autonomic management, scalable agile methods, incremental certification, and system simulation and modelling techniques.These activities span both operational practices and research problems identified in the agenda.
- Education: Education should combine industrial problems with courses on complexity, systems engineering, socio-technical systems, high-integrity engineering, empirical methods, and technology innovation.The EngD model includes substantial industry experience and allows a portfolio of work rather than a conventional single-topic thesis.
- Education: Masters courses for this field must be multidisciplinary, combining engineering and business while exposing students to different disciplinary perspectives.The stated aim is to move students beyond siloed single-discipline thinking.
6. Conclusions
Societies increasingly depend on complex software-intensive systems, yet serious failures can have profound social and economic consequences. The paper concludes that existing software engineering approaches cannot simply be scaled up, so new engineering approaches are needed.
- Complex software-intensive systems now underpin increasing societal dependence, making serious failures potentially profound in their social and economic consequences.
- Existing software engineering approaches cannot be scaled up to create coalitions of systems because their complexity presents fundamental engineering challenges.
- Incremental improvements to current methods are insufficient for coping with the complexity of coalitions of systems.
- Software-intensive systems must be understood as socio-technical systems that include technical, human, and organisational elements.
- System requirements are an inadequate interface with the wider socio-technical system because they are inevitably incomplete, incorrect, and out of date.
- Recognizing coalitions as rich socio-technical systems can harness people's abilities and inventiveness to create more effective and resilient systems.
Authors
The paper lists authors affiliated with universities across Scotland and England.
- Ian Sommerville is a Professor in the School of Computer Science at St Andrews University, Scotland.
- Dave Cliff is a Professor in the Department of Computer Science at Bristol University, England.
- Radu Calinescu is a Lecturer in the Department of Computer Science at Aston University, England.
- Justin Keen is a Professor in the School of Health Informatics at Leeds University, England.
- Tim Kelly, Marta Kwiatkowska, John McDermid, and Richard Paige are computer science or related professors and lecturers at universities in England.