Tardis: A Fault-Tolerant Design for Network Control Planes

Tardis: A Fault-Tolerant Design for Network Control Planes
复制标题

DOI:
10.1145/3482898.3483355
复制
发表时间:
2021-10
期刊:
Proceedings of the ACM SIGCOMM Symposium on SDN Research (SOSR)
影响因子:
--
通讯作者:
Zhenyu Zhou;Theophilus A. Benson;Marco Canini;B. Chandrasekaran
Zhenyu Zhou;Theophilus A. Benson;Marco Canini;B. Chandrasekaran
中科院分区:
其他
文献类型:
--
作者:
Zhenyu Zhou;Theophilus A. Benson;Marco Canini;B. Chandrasekaran

文献摘要

相似文献

保证网络的高可用性实际上取决于处理错误和故障并从错误和故障中恢复的能力。然而,尽管在验证、测试和调试方面取得了进步,但生产网络仍然容易受到大规模故障的影响-通常是由于确定性错误。本文探讨了使用输入转换作为一种可行的方法,从这种确定性的错误恢复。特别是,我们引入了一个在线系统,Tardis,克服确定性故障,通过使用程序分析和运行时程序数据的混合物,系统地确定故障触发输入事件,并使用特定于域的模型自动生成的故障触发输入,是安全的和语义等价的转换。我们评估了Tardison的几个生产网络控制平面应用程序(CPA),包括六个SDN CPA和几个流行的BGP CPA,使用71个真实的错误。我们观察到,Tardi将恢复时间缩短了7.44%,引入了25%的CPU和0.5%的内存开销,并从77.26%的注入现实和代表性错误中恢复,是现有解决方案的两倍多。
Guaranteeing high availability of networks virtually hinges on the ability to handle and recover from bugs and failures. Yet, despite the advances in verification, testing, and debugging, production networks remain susceptible to large-scale failures --- often due to deterministic bugs. This paper explores the use of input transformations as a viable method for recovering from such deterministic bugs. In particular, we introduce an online system, Tardis, for overcoming deterministic faults by using a blend of program analysis and runtime program data to systematically determine the fault-triggering input events and using domain-specific models to automatically generate transformations of the fault-triggering inputs that are both safe and semantically equivalent. We evaluated Tardison several production network control plane applications (CPAs), including six SDN CPAs and several popular BGP CPAs using 71 realistic bugs. We observe that Tardisimproves recovery time by 7.44%, introduces a 25% CPU and 0.5% memory overhead, and recovers from 77.26% of the injected realistic and representative bugs, more than twice that of existing solutions.