Probabilistic Verification of Network Configurations
Probabilistic Verification of Network Configurations
复制标题
网络配置的概率验证
DOI:
--
复制
发表时间:
2020
期刊:
影响因子:
--
通讯作者:
Martin T. Vechev
中科院分区:
文献类型:
--
作者:
Samuel Steffen;Timon Gehr;Petar Tsankov;Laurent Vanbever;Martin T. Vechev
Not all important network properties need to be enforced all the time. Often, what matters instead is the fraction of time / probability these properties hold. Computing the probability of a property in a network relying on complex inter-dependent routing protocols is challenging and requires determining all failure scenarios for which the property is violated. Doing so at scale and accurately goes beyond the capabilities of current network analyzers. In this paper, we introduce NetDice, the first scalable and accurate probabilistic network configuration analyzer supporting BGP, OSPF, ECMP, and static routes. Our key contribution is an inference algorithm to efficiently explore the space of failure scenarios. More specifically, given a network configuration and a property φ, our algorithm automatically identifies a set of links whose failure is provably guaranteed not to change whether φ holds. By pruning these failure scenarios, NetDice manages to accurately approximate P(φ). NetDice supports practical properties and expressive failure models including correlated link failures. We implement NetDice and evaluate it on realistic configurations. NetDice is practical: it can precisely verify probabilistic properties in few minutes, even in large networks.
DOI:
--
发表时间:
2020
期刊:
17th USENIX Symposium on Networked Systems Design and Implementation
影响因子:
--
作者:
Abhashkumar, A.;Gember-Jacobson, A.;Akella, A.
通讯作者:
Akella, A.