跳到主要导航 跳到搜索 跳到主要内容

APKeep: Realtime network verification for real networks

  • Peng Zhang
  • , Xu Liu
  • , Hongkun Yang
  • , Ning Kang
  • , Zhengchang Gu
  • , Hao Li
  • Xi'an Jiaotong University
  • Alphabet Inc.

科研成果: 书/报告/会议事项章节会议稿件同行评审

63 引用 (Scopus)

摘要

Realtime network verification ensures the correctness of network by incrementally checking data plane updates in real time (e.g., < 1ms per rule update). Even state-of-the-art methods can already achieve sub-millisecond verification time, such speed is achieved mostly for pure IP forwarding devices, and is unrealistic for real-world networks, due to two reasons. (1) Their network models cannot express the forwarding behavior of real devices, which have various functions including IP forwarding, ACL, NAT, policy-based routing, etc. (2) Their update algorithms do not scale in space and/or time: multi-field rules (e.g., ACL rules) can make these tools run out of memory and/or incur long verification time. To scale realtime verification to real networks, we propose APKeep based on a new modular network model that is expressive for real devices, and propose new algorithms that can achieve low memory cost and fast update speed at the same time. Our experiments show that for real-world update traces consisting of IP forwarding rules and ACL rules, existing methods either run out of memory or incur a prohibitively long verification time, while APKeep still achieves a sub-millisecond verification time. We also show that APKeep can verify an update of NAT rule mostly in less than 1 millisecond.

源语言英语
主期刊名Proceedings of the 17th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2020
出版商USENIX Association
241-255
页数15
ISBN(电子版)9781939133137
出版状态已出版 - 2020
活动17th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2020 - Santa Clara, 美国
期限: 25 2月 202027 2月 2020

出版系列

姓名Proceedings of the 17th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2020

会议

会议17th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2020
国家/地区美国
Santa Clara
时期25/02/2027/02/20

学术指纹

探究 'APKeep: Realtime network verification for real networks' 的科研主题。它们共同构成独一无二的指纹。

引用此