SPIN Model Checking and Software VerificationKlaus Havelund, John Penix, Willem Visser · First published 2006Open the Tome