Loading...
Please wait, while we are loading the content...
Similar Documents
Good Network Updates for Bad Packets: Waypoint Enforcement Beyond DestinationBased Routing Policies,” in HotNets (2014)
| Content Provider | CiteSeerX |
|---|---|
| Author | Ludwig, Arne Rost, Matthias Foucard, Damien Schmid, Stefan |
| Abstract | Networks are critical for the security of many computer sys-tems. However, their complex and asynchronous nature of-ten renders it difficult to formally reason about network be-havior. Accordingly, it is challenging to provide correctness guarantees, especially during network updates. This paper studies how to update networks while main-taining a most basic safety property, Waypoint Enforce-ment (WPE): each packet is required to traverse a certain checkpoint (for instance, a firewall). Waypoint enforcement is particularly relevant in today’s increasingly virtualized and software-defined networks, where new in-network func-tionality is introduced flexibly. We show that WPE can easily be violated during network updates, even though both the old and the new policy ensure WPE. We then present an algorithm WayUp that guaran-tees WPE at any time, while completing updates quickly. We also find that in contrast to other transient consistency properties, WPE cannot always be implemented in a wait-free manner, and that WPE may even conflict with Loop-Freedom (LF). Finally, we present an optimal policy update algorithm OptRounds, which requires a minimum num-ber of communication rounds while ensuring both WPE and LF, whenever this is possible. |
| File Format | |
| Publisher Date | 2014-01-01 |
| Access Restriction | Open |
| Subject Keyword | Waypoint Enforcement Beyond Bad Packet Good Network Update Routing Policy Network Update New In-network Func-tionality Waypoint Enforcement Certain Checkpoint Minimum Num-ber Many Computer Sys-tems Paper Study Waypoint Enforce-ment Wait-free Manner Transient Consistency Property Software-defined Network Algorithm Wayup Basic Safety Property Optimal Policy Update Algorithm Optrounds Wpe Cannot Correctness Guarantee Asynchronous Nature Of-ten Render Guaran-tees Wpe New Policy Communication Round |
| Content Type | Text |
| Resource Type | Article |