Abstract:The component-based system will provide a predefined survivability specification which consists of corresponding degraded services in the presence of various kinds of malicious attacks,system failures or accidents. The main contributions of this paper are(1) presenting the method to represent service core based on component families and installation orders,which can precisely capture the system services perceived by users;(2) proposing the reasoning rules of system recovery based on component compatibility and installation execution,which are used to judge the success property(the newly started service works well) and safety property (formerly started services are not damaged);and(3) presenting the algorithms to simplify installation execution based on the concept of projection,which supports the reasoning analysis of system recovery of big scale.By the analysis process based on survivability specification,the corresponding reasoning rules can be systemically applied in practice.A component-based system named MVoD(mobile video-on-demand) is illustrated to demonstrate the practicability and efficiency of the formal model and the analysis method.