Modular Control Plane Verification via Temporal Invariants

Modular Control Plane Verification via Temporal Invariants
复制标题

DOI:
10.1145/3591222
复制
发表时间:
2022-04
影响因子:
--
通讯作者:
Timothy Alberdingk Thijm;Ryan Beckett;Aarti Gupta;D. Walker
Timothy Alberdingk Thijm;Ryan Beckett;Aarti Gupta;D. Walker
中科院分区:
--
文献类型:
--
作者:
Timothy Alberdingk Thijm;Ryan Beckett;Aarti Gupta;D. Walker

文献摘要

被引文献

相似文献

整体控制平面验证无法扩展到具有数万个节点,异质网络策略和数千个网络变化的超尺度网络体系结构,而模块化验证可改善我们介绍时间表的推广性,对潜水员的行为进行改进,一个新的模块化控制平面验证系统。稳定的路径,我们表明,当用于模块化验证的幼稚验证时,我们会纠正这种情况要求用户指定模块组件之间的接口。网络范围的属性,例如响应或访问控制,使用80节点FATTREE网络上的非模块化验证引擎时间在2小时后验证2,000个节点FATTREE,并在2.37分钟内验证。一个96核虚拟机。允许基于SMT的符号推理的全部力量。
Monolithic control plane verification cannot scale to hyperscale network architectures with tens of thousands of nodes, heterogeneous network policies and thousands of network changes a day. Instead, modular verification offers improved scalability, reasoning over diverse behaviors, and robustness following policy updates. We introduce Timepiece, a new modular control plane verification system. While one class of verifiers, starting with Minesweeper, were based on analysis of stable paths, we show that such models, when deployed naïvely for modular verification, are unsound. To rectify the situation, we adopt a routing model based around a logical notion of time and develop a sound, expressive, and scalable verification engine. Our system requires that a user specifies interfaces between module components. We develop methods for defining these interfaces using predicates inspired by temporal logic, and show how to use those interfaces to verify a range of network-wide properties such as reachability or access control. Verifying a prefix-filtering policy using a non-modular verification engine times out on an 80-node fattree network after 2 hours. However, Timepiece verifies a 2,000-node fattree in 2.37 minutes on a 96-core virtual machine. Modular verification of individual routers is embarrassingly parallel and completes in seconds, which allows verification to scale beyond non-modular engines, while still allowing the full power of SMT-based symbolic reasoning.