Software EngineeringUnit 915 min read

Software Maintenance & Evolution: Types, Challenges & Strategies

Unit 9 of Software Engineering explores the lifecycle beyond deployment, covering maintenance types (corrective, adaptive, perfective, preventive), evolution drivers (changing requirements, technology shifts), reengineering techniques, and cost-benefit analysis of maintenance activities. It also examines tools, metrics

Key Concepts and Definitions

What is Software Maintenance?

Software maintenance is the modification of a software product after delivery to correct faults, improve performance, or adapt to a changed environment. It is not a one-time activity but an ongoing process that can consume 40–80% of a software’s total lifecycle cost.

stateDiagram-v2
    [*] --> Idle
    Idle --> Active: Deployment
    Active --> Corrective: Fault Reported
    Active --> Adaptive: Environment Change
    Active --> Perfective: User Feedback
    Active --> Preventive: Risk Mitigation
    Active --> [*]: Retirement

Types of Software Maintenance

Maintenance is classified into four main types, each addressing different needs:

CorrectiveAdaptivePerfectivePreventiveIncreasing proactive effort
Maintenance types by proactive intent (e.g., Khalti’s tax API update = Adaptive; Google’s YouTube refactor = Preventive)
Type Definition Example
Corrective Fixing faults found in production (bug fixes). Patching a security vulnerability in eSewa after a data breach.
Adaptive Modifying software to adapt to changes in the operating environment. Updating Khalti to support a new government tax API.
Perfective Enhancing software to improve performance, usability, or functionality. Adding a WhatsApp Pay feature to Pathao for seamless transactions.
Preventive Modifying software to prevent future problems (e.g., refactoring code). Google rewriting parts of YouTube in a more maintainable language to reduce tech debt.

Why Software Evolves: Drivers of Change

Software does not remain static. Key drivers include:

sequenceDiagram
    participant User
    participant BankSystem
    participant Regulator
    participant Competitor
    User->>BankSystem: Requests loan (new KYC rules)
    Regulator->>BankSystem: Updates compliance API
    Competitor->>BankSystem: Adds AI route optimization
    BankSystem-->>User: Approves loan with new features
    Note right of BankSystem: Drivers: Requirements, Regulations, Competition
Sequence of real-world drivers (Nabil Bank’s loan system example)
  1. Changing User Requirements

    • Example: Nepal Rastra Bank (NRB) mandates new KYC (Know Your Customer) rules for banks → Nabil Bank must update its loan processing software.
  2. Technological Advancements

    • Example: Daraz migrates from monolithic architecture to microservices to handle increased traffic during sales.
  3. Legal and Regulatory Changes

    • Example: NTC updates its billing software to comply with new GDPR-like data privacy laws in Nepal.
  4. Performance and Security Issues

    • Example: Ncell patches its mobile app after a DDoS attack exposes a flaw in its authentication system.
  5. Competitive Pressures

    • Example: Pathao adds AI-driven route optimization to compete with Karma Taxi.

IMAGE: server rack in data center | Hardware infrastructure supporting software maintenance (e.g., patch deployment, backups)


Software Maintenance Process

The process involves planning, implementation, and review in a structured workflow:

flowchart TD
    A["Maintenance Request"] --> B{"Type of Maintenance?"}
    B -->|"Corrective"| C["Debugging & Fix"]
    B -->|"Adaptive"| D["Environment Analysis"]
    B -->|"Perfective"| E["Feature Enhancement"]
    B -->|"Preventive"| F["Refactoring/Redesign"]
    C --> G["Testing"]
    D --> G
    E --> G
    F --> G
    G --> H["Deployment"]
    H --> I["User Feedback/Monitoring"]
    I -->|"Loop"| A

Steps in Detail:

  1. Request Analysis

    • Prioritize based on severity, impact, and cost.
    • Example: A bank’s core banking system crash during Diwali season (high priority) vs. a minor UI glitch (low priority).
  2. Impact Analysis

    • Assess how changes affect other modules, performance, and security.
    • Example: Updating NEPSE’s trading software may require load testing to handle increased volume.
  3. Modification and Testing

    • Use unit, integration, and regression testing.
    • Example: Khalti tests a new two-factor authentication feature with real users before full rollout.
  4. Implementation

    • Deploy fixes in stages (e.g., canary releases for YouTube updates).
  5. Review and Documentation

    • Update user manuals, API docs, and code comments.
    • Example: Google maintains a public changelog for Android updates.

Software Reengineering and Reverse Engineering

When maintenance becomes too costly, reengineering (restructuring existing software) or reverse engineering (analyzing undocumented code) is used.

Extract design specsDecompile to PythonReverse EngineeringRefactor modulesCloud migrationReengineeringLegacy System (COBOL)
NTC’s billing system reengineering path (20-year-old → modern stack)
Technique Definition Example
Reengineering Redesigning, recoding, or restructuring software to improve quality. NTC rewrites its old billing system in Python from legacy COBOL.
Reverse Engineering Analyzing software to extract design info (e.g., for maintenance or migration). Security researchers decompile a malware sample to understand its attack vector.
Forward Engineering Building a new system from scratch based on reverse-engineered requirements. Nepal Rastra Bank replaces its 20-year-old core banking system with a modern cloud-based solution.

IMAGE: motherboard with CPU and RAM | Hardware constraints (e.g., legacy systems) often drive software reengineering


Cost of Software Maintenance

Maintenance costs can be high but necessary. A study by IBM found that software maintenance accounts for 60–80% of total lifecycle costs.

Cost Factors:

  • Direct Costs: Labor, tools, testing.
  • Indirect Costs: Downtime, lost revenue, user dissatisfaction.
  • Example: Daraz’s website crash during Dashain sales costs millions in lost sales.

Cost Estimation Models:

  1. Function Point Analysis (FPA)
    • Measures maintenance effort based on function points (inputs, outputs, queries).
    • Example: A bank’s loan processing module with 500 function points may cost $50,000/year to maintain.
011.2522.533.7545Corrective45Adaptive30Perfective20Preventive5
IBM study: % of maintenance effort by type (Nepal’s NEPSE trading system: 60% corrective during Diwali)
  1. COCOMO Model
    • Estimates effort based on lines of code (LOC) and complexity.
    • Example: A 100,000 LOC system may require 2 person-years for corrective maintenance.

Tools for Software Maintenance

Category Tools Use Case
Version Control Git, SVN Track changes in eSewa’s payment gateway code.
Debugging GDB, Visual Studio Debugger, PyCharm Fixing a crash in Ncell’s mobile app.
Static Analysis SonarQube, Checkstyle Detecting code smells in Khalti’s transaction logs.
Dynamic Analysis JMeter, LoadRunner Testing Daraz’s server under high traffic.
Configuration Management Ansible, Puppet Deploying patches to NTC’s nationwide network.
Documentation Doxygen, Swagger Generating API docs for NEPSE’s trading system.

IMAGE: GitHub interface showing commit history | Version control tools track every change in software evolution


Challenges in Software Maintenance

  1. Legacy Systems

    • Example: Nepal’s old land record system runs on 1990s COBOL and lacks modern APIs.
  2. Lack of Documentation

    • Example: A bank’s retired developer leaves without documenting a critical module.
  3. Changing Technology

    • Example: WhatsApp must constantly update its end-to-end encryption to counter new threats.
  4. User Resistance

    • Example: Elderly users of eSewa may reject a new biometric login system.
  5. Security Risks

    • Example: Pathao’s old SQL queries are vulnerable to SQL injection attacks.

Strategies for Effective Maintenance

  1. Modular Design

    • Example: Google’s microservices architecture allows teams to update YouTube’s recommendation engine independently.
  2. Automated Testing

    • Example: Khalti uses CI/CD pipelines to auto-test every commit.
  3. Regular Refactoring

    • Example: Facebook spends 20% of dev time on refactoring to reduce technical debt.
  4. User Feedback Loops

    • Example: Daraz uses surveys and analytics to prioritize maintenance requests.
  5. Training and Knowledge Transfer

    • Example: NTC conducts workshops for engineers maintaining its legacy switching systems.

In the Real World

  1. eSewa’s Maintenance Challenges

    • Problem: During Dashain, eSewa’s servers crash due to unexpected transaction spikes.
    • Solution: They implemented auto-scaling in AWS and caching mechanisms to handle load.
    • Lesson: Perfective maintenance (performance tuning) is critical for high-traffic systems.
  2. Khalti’s Adaptive Maintenance

    • Problem: Nepal Rastra Bank introduces new KYC rules.
    • Solution: Khalti’s team spent 3 months updating its identity verification module.
    • Lesson: Adaptive maintenance ensures compliance and avoids legal penalties.
  3. NEPSE’s Corrective Maintenance

    • Problem: A bug in NEPSE’s trading software causes false buy/sell orders.
    • Solution: Emergency patch deployed during market hours with rollback plans.
    • Lesson: Corrective maintenance must be fast and reliable to prevent financial losses.

Worked Example: Maintaining a Bank’s Loan Processing System

Scenario: A bank’s loan approval system is slow during peak hours (e.g., Diwali season). The IT team must decide how to fix it.

Step 1: Identify the Maintenance Type

  • Problem: Performance bottleneck → Perfective maintenance (enhancement).
  • Alternative: If the system crashes → Corrective maintenance.

Step 2: Analyze the Root Cause

  • Possible Causes:
    • Inefficient SQL queries.
    • Lack of database indexing.
    • Monolithic architecture slowing down requests.

Step 3: Propose Solutions

Solution Type Cost Risk Benefit
Optimize SQL queries Perfective Low Low (tested in staging) Faster response time
Add database caching Perfective Medium Medium (cache invalidation) Reduces DB load
Migrate to microservices Reengineering High High (complex migration) Scalable, independent updates

Step 4: Choose and Implement

  • Best Option: Optimize queries + add caching (balanced cost/benefit).
  • Tools Used:
    • SQL Profiler (to find slow queries).
    • Redis (for caching).
    • Load testing (to verify improvements).

Step 5: Monitor and Iterate

  • Post-deployment: Track response times and user feedback.
  • Feedback: If issues persist, consider microservices in the next phase.

Exam Tip

What Examiners Look For:

  1. Clear Classification

    • Always distinguish between corrective, adaptive, perfective, and preventive maintenance with real-world examples.
    • Example: "eSewa’s security patch is corrective, while its new OTP feature is perfective."
  2. Cost-Benefit Analysis

    • Exams often ask: "Which maintenance strategy is best for [scenario]?"
    • Structure your answer:
      • Identify the type of maintenance needed.
      • List pros/cons of each option.
      • Justify your choice with cost, risk, and benefit.
  3. Tools and Techniques

    • Know at least 2 tools for each maintenance activity (e.g., Git for version control, SonarQube for static analysis).
    • Example: "For reverse engineering, tools like JAD (Joint Application Design) and decompilers are used."
  4. Real-World Scenarios

    • Always tie answers to Nepalese or global companies (e.g., NTC’s legacy systems, Khalti’s compliance updates).
    • Example: "NEPSE’s trading system requires high availability, so preventive maintenance (like load testing) is critical."
  5. Diagrams and Flowcharts

    • Draw maintenance process flows (like the one above) to visualize steps.
    • Use tables to compare costs, risks, and benefits of different strategies.

Common Pitfalls to Avoid:

  • Vague Answers: Instead of "maintenance is important", say "adaptive maintenance ensures Khalti complies with NRB’s new API standards."
  • Ignoring Trade-offs: Always discuss cost vs. benefit (e.g., "Refactoring is expensive but reduces technical debt long-term.").
  • Overlooking Documentation: Maintenance fails without proper logs and docs—mention this in answers.

Final Checklist for Full Marks:

✅ Define software maintenance and its four types with Nepali examples. ✅ Explain why software evolves (requirements, tech, laws) with real cases. ✅ Describe the maintenance process (request → analysis → modification → testing → deployment). ✅ Compare reengineering vs. reverse engineering with a Nepalese system (e.g., NTC’s old switches). ✅ Discuss cost models (COCOMO, FPA) and tools (Git, SonarQube). ✅ Solve a worked example (e.g., bank loan system) with step-by-step reasoning. ✅ Link to real-world apps (eSewa, Khalti, NEPSE) in every major section.

Based on the PU BE Computer (PU) syllabus for Software Engineering (CMP348), unit 9.

Discussion

Loading…