Software EngineeringUnit 915 min read
Software Maintenance & Evolution: Types, Challenges & Strategies
Unit 9 of Software Engineering explores the lifecycle beyond deployment, covering maintenance types (corrective, adaptive, perfective, preventive), evolution drivers (changing requirements, technology shifts), reengineering techniques, and cost-benefit analysis of maintenance activities. It also examines tools, metrics
Key Concepts and Definitions
What is Software Maintenance?
Software maintenance is the modification of a software product after delivery to correct faults, improve performance, or adapt to a changed environment. It is not a one-time activity but an ongoing process that can consume 40–80% of a software’s total lifecycle cost.
stateDiagram-v2
[*] --> Idle
Idle --> Active: Deployment
Active --> Corrective: Fault Reported
Active --> Adaptive: Environment Change
Active --> Perfective: User Feedback
Active --> Preventive: Risk Mitigation
Active --> [*]: RetirementTypes of Software Maintenance
Maintenance is classified into four main types, each addressing different needs:
| Type | Definition | Example |
|---|---|---|
| Corrective | Fixing faults found in production (bug fixes). | Patching a security vulnerability in eSewa after a data breach. |
| Adaptive | Modifying software to adapt to changes in the operating environment. | Updating Khalti to support a new government tax API. |
| Perfective | Enhancing software to improve performance, usability, or functionality. | Adding a WhatsApp Pay feature to Pathao for seamless transactions. |
| Preventive | Modifying software to prevent future problems (e.g., refactoring code). | Google rewriting parts of YouTube in a more maintainable language to reduce tech debt. |
Why Software Evolves: Drivers of Change
Software does not remain static. Key drivers include:
sequenceDiagram
participant User
participant BankSystem
participant Regulator
participant Competitor
User->>BankSystem: Requests loan (new KYC rules)
Regulator->>BankSystem: Updates compliance API
Competitor->>BankSystem: Adds AI route optimization
BankSystem-->>User: Approves loan with new features
Note right of BankSystem: Drivers: Requirements, Regulations, CompetitionSequence of real-world drivers (Nabil Bank’s loan system example)Changing User Requirements
- Example: Nepal Rastra Bank (NRB) mandates new KYC (Know Your Customer) rules for banks → Nabil Bank must update its loan processing software.
Technological Advancements
- Example: Daraz migrates from monolithic architecture to microservices to handle increased traffic during sales.
Legal and Regulatory Changes
- Example: NTC updates its billing software to comply with new GDPR-like data privacy laws in Nepal.
Performance and Security Issues
- Example: Ncell patches its mobile app after a DDoS attack exposes a flaw in its authentication system.
Competitive Pressures
- Example: Pathao adds AI-driven route optimization to compete with Karma Taxi.
IMAGE: server rack in data center | Hardware infrastructure supporting software maintenance (e.g., patch deployment, backups)
Software Maintenance Process
The process involves planning, implementation, and review in a structured workflow:
flowchart TD
A["Maintenance Request"] --> B{"Type of Maintenance?"}
B -->|"Corrective"| C["Debugging & Fix"]
B -->|"Adaptive"| D["Environment Analysis"]
B -->|"Perfective"| E["Feature Enhancement"]
B -->|"Preventive"| F["Refactoring/Redesign"]
C --> G["Testing"]
D --> G
E --> G
F --> G
G --> H["Deployment"]
H --> I["User Feedback/Monitoring"]
I -->|"Loop"| ASteps in Detail:
Request Analysis
- Prioritize based on severity, impact, and cost.
- Example: A bank’s core banking system crash during Diwali season (high priority) vs. a minor UI glitch (low priority).
Impact Analysis
- Assess how changes affect other modules, performance, and security.
- Example: Updating NEPSE’s trading software may require load testing to handle increased volume.
Modification and Testing
- Use unit, integration, and regression testing.
- Example: Khalti tests a new two-factor authentication feature with real users before full rollout.
Implementation
- Deploy fixes in stages (e.g., canary releases for YouTube updates).
Review and Documentation
- Update user manuals, API docs, and code comments.
- Example: Google maintains a public changelog for Android updates.
Software Reengineering and Reverse Engineering
When maintenance becomes too costly, reengineering (restructuring existing software) or reverse engineering (analyzing undocumented code) is used.
| Technique | Definition | Example |
|---|---|---|
| Reengineering | Redesigning, recoding, or restructuring software to improve quality. | NTC rewrites its old billing system in Python from legacy COBOL. |
| Reverse Engineering | Analyzing software to extract design info (e.g., for maintenance or migration). | Security researchers decompile a malware sample to understand its attack vector. |
| Forward Engineering | Building a new system from scratch based on reverse-engineered requirements. | Nepal Rastra Bank replaces its 20-year-old core banking system with a modern cloud-based solution. |
IMAGE: motherboard with CPU and RAM | Hardware constraints (e.g., legacy systems) often drive software reengineering
Cost of Software Maintenance
Maintenance costs can be high but necessary. A study by IBM found that software maintenance accounts for 60–80% of total lifecycle costs.
Cost Factors:
- Direct Costs: Labor, tools, testing.
- Indirect Costs: Downtime, lost revenue, user dissatisfaction.
- Example: Daraz’s website crash during Dashain sales costs millions in lost sales.
Cost Estimation Models:
- Function Point Analysis (FPA)
- Measures maintenance effort based on function points (inputs, outputs, queries).
- Example: A bank’s loan processing module with 500 function points may cost $50,000/year to maintain.
- COCOMO Model
- Estimates effort based on lines of code (LOC) and complexity.
- Example: A 100,000 LOC system may require 2 person-years for corrective maintenance.
Tools for Software Maintenance
| Category | Tools | Use Case |
|---|---|---|
| Version Control | Git, SVN | Track changes in eSewa’s payment gateway code. |
| Debugging | GDB, Visual Studio Debugger, PyCharm | Fixing a crash in Ncell’s mobile app. |
| Static Analysis | SonarQube, Checkstyle | Detecting code smells in Khalti’s transaction logs. |
| Dynamic Analysis | JMeter, LoadRunner | Testing Daraz’s server under high traffic. |
| Configuration Management | Ansible, Puppet | Deploying patches to NTC’s nationwide network. |
| Documentation | Doxygen, Swagger | Generating API docs for NEPSE’s trading system. |
IMAGE: GitHub interface showing commit history | Version control tools track every change in software evolution
Challenges in Software Maintenance
Legacy Systems
- Example: Nepal’s old land record system runs on 1990s COBOL and lacks modern APIs.
Lack of Documentation
- Example: A bank’s retired developer leaves without documenting a critical module.
Changing Technology
- Example: WhatsApp must constantly update its end-to-end encryption to counter new threats.
User Resistance
- Example: Elderly users of eSewa may reject a new biometric login system.
Security Risks
- Example: Pathao’s old SQL queries are vulnerable to SQL injection attacks.
Strategies for Effective Maintenance
Modular Design
- Example: Google’s microservices architecture allows teams to update YouTube’s recommendation engine independently.
Automated Testing
- Example: Khalti uses CI/CD pipelines to auto-test every commit.
Regular Refactoring
- Example: Facebook spends 20% of dev time on refactoring to reduce technical debt.
User Feedback Loops
- Example: Daraz uses surveys and analytics to prioritize maintenance requests.
Training and Knowledge Transfer
- Example: NTC conducts workshops for engineers maintaining its legacy switching systems.
In the Real World
eSewa’s Maintenance Challenges
- Problem: During Dashain, eSewa’s servers crash due to unexpected transaction spikes.
- Solution: They implemented auto-scaling in AWS and caching mechanisms to handle load.
- Lesson: Perfective maintenance (performance tuning) is critical for high-traffic systems.
Khalti’s Adaptive Maintenance
- Problem: Nepal Rastra Bank introduces new KYC rules.
- Solution: Khalti’s team spent 3 months updating its identity verification module.
- Lesson: Adaptive maintenance ensures compliance and avoids legal penalties.
NEPSE’s Corrective Maintenance
- Problem: A bug in NEPSE’s trading software causes false buy/sell orders.
- Solution: Emergency patch deployed during market hours with rollback plans.
- Lesson: Corrective maintenance must be fast and reliable to prevent financial losses.
Worked Example: Maintaining a Bank’s Loan Processing System
Scenario: A bank’s loan approval system is slow during peak hours (e.g., Diwali season). The IT team must decide how to fix it.
Step 1: Identify the Maintenance Type
- Problem: Performance bottleneck → Perfective maintenance (enhancement).
- Alternative: If the system crashes → Corrective maintenance.
Step 2: Analyze the Root Cause
- Possible Causes:
- Inefficient SQL queries.
- Lack of database indexing.
- Monolithic architecture slowing down requests.
Step 3: Propose Solutions
| Solution | Type | Cost | Risk | Benefit |
|---|---|---|---|---|
| Optimize SQL queries | Perfective | Low | Low (tested in staging) | Faster response time |
| Add database caching | Perfective | Medium | Medium (cache invalidation) | Reduces DB load |
| Migrate to microservices | Reengineering | High | High (complex migration) | Scalable, independent updates |
Step 4: Choose and Implement
- Best Option: Optimize queries + add caching (balanced cost/benefit).
- Tools Used:
- SQL Profiler (to find slow queries).
- Redis (for caching).
- Load testing (to verify improvements).
Step 5: Monitor and Iterate
- Post-deployment: Track response times and user feedback.
- Feedback: If issues persist, consider microservices in the next phase.
Exam Tip
What Examiners Look For:
Clear Classification
- Always distinguish between corrective, adaptive, perfective, and preventive maintenance with real-world examples.
- Example: "eSewa’s security patch is corrective, while its new OTP feature is perfective."
Cost-Benefit Analysis
- Exams often ask: "Which maintenance strategy is best for [scenario]?"
- Structure your answer:
- Identify the type of maintenance needed.
- List pros/cons of each option.
- Justify your choice with cost, risk, and benefit.
Tools and Techniques
- Know at least 2 tools for each maintenance activity (e.g., Git for version control, SonarQube for static analysis).
- Example: "For reverse engineering, tools like JAD (Joint Application Design) and decompilers are used."
Real-World Scenarios
- Always tie answers to Nepalese or global companies (e.g., NTC’s legacy systems, Khalti’s compliance updates).
- Example: "NEPSE’s trading system requires high availability, so preventive maintenance (like load testing) is critical."
Diagrams and Flowcharts
- Draw maintenance process flows (like the one above) to visualize steps.
- Use tables to compare costs, risks, and benefits of different strategies.
Common Pitfalls to Avoid:
- Vague Answers: Instead of "maintenance is important", say "adaptive maintenance ensures Khalti complies with NRB’s new API standards."
- Ignoring Trade-offs: Always discuss cost vs. benefit (e.g., "Refactoring is expensive but reduces technical debt long-term.").
- Overlooking Documentation: Maintenance fails without proper logs and docs—mention this in answers.
Final Checklist for Full Marks:
✅ Define software maintenance and its four types with Nepali examples. ✅ Explain why software evolves (requirements, tech, laws) with real cases. ✅ Describe the maintenance process (request → analysis → modification → testing → deployment). ✅ Compare reengineering vs. reverse engineering with a Nepalese system (e.g., NTC’s old switches). ✅ Discuss cost models (COCOMO, FPA) and tools (Git, SonarQube). ✅ Solve a worked example (e.g., bank loan system) with step-by-step reasoning. ✅ Link to real-world apps (eSewa, Khalti, NEPSE) in every major section.
Based on the PU BE Computer (PU) syllabus for Software Engineering (CMP348), unit 9.
Discussion
Loading…