Aaron Gember

dblp:07/9556 · also Aaron Gember-Jacobson · DBLP profile ↗
← Back
24ranked-venue papers
10as first author
5since 2021 · last 2024
0000-0003-3771-7876ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 20 · 8 first-author · 5 since 2021Software engineering, systems software and programming languages · 3 · 1 first-authorSystems, architecture and hardware · 1Security and privacy · 1 · 1 first-author
YearPublicationVenuePosition
2024 Expresso: Comprehensively Reasoning About External Routes Using Symbolic Simulation
abstract
Existing network verifiers can efficiently identify failure-induced bugs. However, an equally-important concern is identification of external-routes-induced bugs, which has not been well addressed. Comprehensively reasoning about external routes is challenging, since each external neighbor can advertise an arbitrary set of routes, which is quite a huge space. This paper introduces a new network verifier, Expresso, which uses symbolic simulation to explore the equivalences in the space of external routes. We evaluate the effectiveness and scalability of Expresso on the WAN of a large cloud service provider and Internet2. Expresso found various property violations, some of which have already been confirmed by the operators. To the best of our knowledge, Expresso is the only verifier that can check the correctness of WANs amidst arbitrary external routes in a tractable amount of time, while other verifiers time-out after 1 day.
Peng Zhang 0011, Aaron Gember
SIGCOMM3
2023 Generative, High-Fidelity Network Traces
abstract
Recently, much attention has been devoted to the development of generative network traces and their potential use in supplementing real-world data for a variety of data-driven networking tasks. Yet, the utility of existing synthetic traffic approaches are limited by their low fidelity: low feature granularity, insufficient adherence to task constraints, and subpar class coverage. As effective network tasks are increasingly reliant on raw packet captures, we advocate for a paradigm shift from coarse-grained to fine-grained traffic generation compliant to constraints. We explore this path employing controllable diffusion-based methods. Our preliminary results suggest its effectiveness in generating realistic and fine-grained network traces that mirror the complexity and variety of real network traffic required for accurate service recognition. We further outline the challenges and opportunities of this approach, and discuss a research agenda towards text-to-traffic synthesis.
Xi Jiang 0007, Shinan Liu, Aaron Gember, Paul Schmitt, Francesco Bronzino, Nick Feamster
HotNets3
2022 Poster: Identifying Syntactic Motifs and Errors in Router Configurations Using Graphs
abstract
Router configurations are complex, so misconfigurations are common and hard to pinpoint. Existing configuration verifiers have several drawbacks. Consequently, we design a three stage heuristic to represent a wide range of components and relationships from a network's raw configurations as a graph, and we infer which of the aforementioned components refer to each other often by finding cycles in the graph. Deviations from frequently occurring cycles are considered misconfigurations.
Sara Alam, Devon Lee, Aaron Gember
ICNP3
2022 Differential Network Analysis
Peng Zhang 0011, Aaron Gember, Yueshang Zuo, Xu Liu 0013, Hao Li 0011
NSDI2
2022 Symbolic router execution
abstract
Network verification often requires analyzing properties across different spaces (header space, failure space, or their product) under different failure models (deterministic and/or probabilistic). Existing verifiers efficiently cover the header or failure space, but not both, and efficiently reason about deterministic or probabilistic failures, but not both. Consequently, no single verifier can support all analyses that require different space coverage and failure models. This paper introduces Symbolic Router Execution (SRE), a general and scalable verification engine that supports various analyses. SRE symbolically executes the network model to discover what we call packet failure equivalence classes (PFECs), each of which characterises a unique forwarding behavior across the product space of headers and failures. SRE enables various optimizations during the symbolic execution, while remaining agnostic of the failure model, so it scales to the product space in a general way. By using BDDs to encode symbolic headers and failures, various analyses reduce to graph algorithms (e.g., shortest-path) on the BDDs. Our evaluation using real and synthetic topologies show SRE achieves better or comparable performance when checking reachability, mining specifications, etc. compared to state-of-the-art methods.
Peng Zhang 0011, Aaron Gember
SIGCOMM3
2020 AED: incrementally synthesizing policy-compliant and manageable configurations
abstract
When updating router configurations, network operators often attempt to meet a variety of management objectives (e.g., maintaining structural similarity across devices), while also ensuring all forwarding policies are correctly satisfied. Our tool, AED, automates this process. AED models configuration updates as a collection of syntax tree additions and removals, and formulates an innovative system of SMT (Satisfiability Modulo Theory) constraints that encode configurations' structure and interaction with routing algorithms. Operators express management objectives in a high-level language, and AED translates these to "soft" constraints that are maximally satisfied. Evaluations on real and synthetic network configurations show that AED can update networks with tens of routers and hundreds of policies in under a minute, and AED outperforms both hand-crafted updates and state-of-the-art tools in meeting management objectives.
Anubhavnidhi Abhashkumar, Aaron Gember, Aditya Akella
CoNEXT2
2020 Incremental Network Configuration Verification
abstract
Network configurations are constantly changing, and each change poses a risk of catastrophic network outages. Consequently, the networking community has put significant effort into developing and optimizing configuration verifiers. However, we observe existing configuration verifiers still have a significant drawback: they are not optimized for configuration changes. That is, they always check a snapshot of network configuration from scratch, even though the configuration often changes slightly since the last verification. In this paper, we demonstrate the benefits, opportunities, and challenges of incremental network configuration verification (INCV). We also demonstrate the feasibility of INCV by introducing RealConfig, an incremental configuration verifier that can check configuration changes within one second.
Peng Zhang 0011, Aaron Gember, Xu Liu 0013, Hongkun Yang, Zhiqiang Zuo 0002
HotNets3
2020 Tiramisu: Fast Multilayer Network Verification
Anubhavnidhi Abhashkumar, Aaron Gember, Aditya Akella
NSDI2
2017 Integrating Verification and Repair into the Control Plane
abstract
Network verification has made great progress recently, yet existing solutions are limited in their ability to handle specific protocols or implementation quirks or to diagnose and repair the cause of policy violations. In this positioning paper, we examine whether we can achieve the best of both worlds: full coverage of control plane protocols and decision processes combined with the ability to diagnose and repair the cause of violations. To this end, we leverage the happens-before relationships that exist between control plane I/Os (e.g., route advertisements and forwarding updates). These relationships allow us to identify when it is safe to employ a data plane verifier and track the root-cause of problematic forwarding updates. We show how we can capture errors before they are installed, automatically trace down the source of the error and roll-back the updates whenever possible.
Aaron Gember, Costin Raiciu, Laurent Vanbever
HotNets1
2017 Automatically Repairing Network Control Planes Using an Abstract Representation
abstract
The forwarding behavior of computer networks is governed by the configuration of distributed routing protocols and access filters---collectively known as the network control plane. Unfortunately, control plane configurations are often buggy, causing networks to violate important policies: e.g., specific traffic classes (defined in terms of source and destination endpoints) should always be able to reach their destination, or always traverse a waypoint. Manually repairing these configurations is daunting because of their inter-twined nature across routers, traffic classes, and policies.
Aaron Gember, Aditya Akella, Ratul Mahajan, Hongqiang Harry Liu
SOSP1
2016 Paving the Way for NFV: Simplifying Middlebox Modifications Using StateAlyzr
Junaid Khalid, Aaron Gember, Roney Michael, Anubhavnidhi Abhashkumar, Aditya Akella
NSDI2
2016 Fast Control Plane Analysis Using an Abstract Representation
abstract
Networks employ complex, and hence error-prone, routing control plane configurations. In many cases, the impact of errors manifests only under failures and leads to devastating effects. Thus, it is important to proactively verify control plane behavior under arbitrary link failures. State-of-the-art verifiers are either too slow or impractical to use for such verification tasks. In this paper we propose a new high level abstraction for control planes, ARC, that supports fast control plane analyses under arbitrary failures. ARC can check key invariants without generating the data plane--which is the main reason for current tools' ineffectiveness. This is possible because of the nature of verification tasks and the constrained nature of control plane designs in networks today. We develop algorithms to derive a network's ARC from its configuration files. Our evaluation over 314 networks shows that ARC computation is quick, and that ARC can verify key invariants in under 1s in most cases, which is orders-of-magnitude faster than the state-of-the-art.
Aaron Gember, Raajay Viswanathan, Aditya Akella, Ratul Mahajan
SIGCOMM1
2015 Management Plane Analytics
abstract
While it is generally held that network management is tedious and error-prone, it is not well understood which specific management practices increase the risk of failures. Indeed, our survey of 51 network operators reveals a significant diversity of opinions, and our characterization of the management practices in the 850+ networks of a large online service provider shows significant diversity in prevalent practices. Motivated by these observations, we develop a management plane analytics (MPA) framework that an organization can use to: (i) infer which management practices impact network health, and (ii) develop a predictive model of health, based on observed practices, to improve network management. We overcome the challenges of sparse and skewed data by aggregating data from many networks, reducing data dimensionality, and oversampling minority cases. Our learned models predict network health with an accuracy of 76-89%, and our causal analysis uncovers some high impact practices that operators thought had a low impact on network health. Our tool is publicly available, so organizations can analyze their own management practices.
Aaron Gember, Wenfei Wu, Xiujun Li, Aditya Akella, Ratul Mahajan
Internet Measurement Conference1
2015 Latency in Software Defined Networks: Measurements and Mitigation Techniques
abstract
We conduct a comprehensive measurement study of switch control plane latencies using four types of production SDN switches. Our measurements show that control actions, such as rule installation, have surprisingly high latency, due to both software implementation inefficiencies and fundamental traits of switch hardware. We also propose three measurement-driven latency mitigation techniques---optimizing route selection, spreading rules across switches, and reordering rule installations---to effectively tame the flow setup latencies in SDN.
Keqiang He, Junaid Khalid, Aaron Gember, Chaithan Prakash, Aditya Akella, Li Erran Li, Marina Thottan
SIGMETRICS4
2014 Design patterns for tunable and efficient SSD-based indexes
abstract
A number of data-intensive systems require using random hash-based indexes of various forms, e.g., hash tables, Bloom filters, and locality sensitive hash tables. In this paper, we present general SSD optimization techniques that can be used to design a variety of such indexes while ensuring higher performance and easier tunability than specialized state-of-the-art approaches. We leverage two key SSD innovations: a) rearranging the data layout on the SSD to combine multiple read requests into one page read, and b) intelligently reordering requests to exploit inherent parallelism in the architecture of SSDs. We build three different indexes using these techniques, and we conduct extensive studies showing their superior performance, lower CPU/memory footprint, and tunability compared to state-of-the-art systems.
Ashok Anand, Aaron Gember, Collin Engstrom, Aditya Akella
ANCS2
2014 VeriCon: towards verifying controller programs in software-defined networks
abstract
Software-defined networking (SDN) is a new paradigm for operating and managing computer networks. SDN enables logically-centralized control over network devices through a "controller" software that operates independently from the network hardware, and can be viewed as the network operating system. Network operators can run both inhouse and third-party SDN programs (often called applications) on top of the controller, e.g., to specify routing and access control policies. SDN opens up the possibility of applying formal methods to prove the correctness of computer networks. Indeed, recently much effort has been invested in applying finite state model checking to check that SDN programs behave correctly. However, in general, scaling these methods to large networks is challenging and, moreover, they cannot guarantee the absence of errors.
Thomas Ball 0001, Nikolaj S. Bjørner, Aaron Gember, Shachar Itzhaky, Aleksandr Karbyshev, Shmuel Sagiv, Michael Schapira, Asaf Valadarsky
PLDI3
2014 OpenNF: enabling innovation in network function control
abstract
Network functions virtualization (NFV) together with software-defined networking (SDN) has the potential to help operators satisfy tight service level agreements, accurately monitor and manipulate network traffic, and minimize operating expenses. However, in scenarios that require packet processing to be redistributed across a collection of network function (NF) instances, simultaneously achieving all three goals requires a framework that provides efficient, coordinated control of both internal NF state and network forwarding state. To this end, we design a control plane called OpenNF. We use carefully designed APIs and a clever combination of events and forwarding updates to address race conditions, bound overhead, and accommodate a variety of NFs. Our evaluation shows that OpenNF offers efficient state control without compromising flexibility, and requires modest additions to NFs.
Aaron Gember, Raajay Viswanathan, Chaithan Prakash, Robert Grandl, Junaid Khalid, Aditya Akella
SIGCOMM1
2013 Next stop, the cloud: understanding modern web service deployment in EC2 and azure
abstract
An increasingly large fraction of Internet services are hosted on a cloud computing system such as Amazon EC2 or Windows Azure. But to date, no in-depth studies about cloud usage by Internet services has been performed. We provide a detailed measurement study to shed light on how modern web service deployments use the cloud and to identify ways in which cloud-using services might improve these deployments. Our results show that: 4% of the Alexa top million use EC2/Azure; there exist several common deployment patterns for cloud-using web service front ends; and services can significantly improve their wide-area performance and failure tolerance by making better use of existing regional diversity in EC2. Driving these analyses are several new datasets, including one with over 34 million DNS records for Alexa websites and a packet capture from a large university network.
Keqiang He, Alexis Fisher, Liang Wang 0023, Aaron Gember, Aditya Akella, Thomas Ristenpart
Internet Measurement Conference4
2013 Design and implementation of a framework for software-defined middlebox networking
abstract
No abstract available.
Aaron Gember, Robert Grandl, Junaid Khalid, Aditya Akella
SIGCOMM1
2012 ECOS: leveraging software-defined networks to support mobile application offloading
abstract
Offloading has emerged as a promising idea to allow resource-constrained mobile devices to access intensive applications, without performance or energy costs, by leveraging external computing resources. This could be particularly useful in enterprise contexts where running line-of-business applications on mobile devices can enhance enterprise operations. However, we must address three practical roadblocks to make offloading amenable to adoption by enterprises: (i) ensuring privacy and trustworthiness of offload, (ii) decoupling offloading systems from their reliance on the availability of dedicated resources and (iii) accommodating offload at scale. We present the design and implementation of ECOS, an enterprise-centric offloading framework that leverages Software-Defined Networking to augment prior offloading proposals and address these limitations. ECOS functions as an application running at an enterprise-wide controller to allocate resources to mobile applications based on privacy and performance requirements, to ensure fairness, and to enforce security constraints. Experiments using a prototype based on Android and OpenFlow establish the effectiveness of our approach.
Aaron Gember, Chris Dragga, Aditya Akella
ANCS1
2012 Toward software-defined middlebox networking
abstract
Current middlebox (MB) management mechanisms are clumsy and unsuitable for taking full advantage of new MB deployment models and diverse MB functionality. Instead, we advocate for mechanisms that help exercise unified control over the key factors influencing MB operations. Our goal is to realize a software-defined MB networking framework to simplify management of complex, diverse functionalities and engender rich deployments. We discuss the major challenges that arise---representing, manipulating, and knowledgeably controlling MB state---and we present initial thoughts on the appropriate abstractions and interfaces to address them.
Aaron Gember, Prathmesh Prabhu, Zainab Ghadiyali, Aditya Akella
HotNets1
2012 Obtaining in-context measurements of cellular network performance
abstract
Network service providers, and other parties, require an accurate understanding of the performance cellular networks deliver to users. In particular, they often seek a measure of the network performance users experience solely when they are interacting with their device---a measure we call in-context. Acquiring such measures is challenging due to the many factors, including time and physical context, that influence cellular network performance. This paper makes two contributions. First, we conduct a large scale measurement study, based on data collected from a large cellular provider and from hundreds of controlled experiments, to shed light on the issues underlying in-context measurements. Our novel observations show that measurements must be conducted on devices which (i) recently used the network as a result of user interaction with the device, (ii) remain in the same macro-environment (e.g., indoors and stationary), and in some cases the same micro-environment (e.g., in the user's hand), during the period between normal usage and a subsequent measurement, and (iii) are currently sending/ receiving little or no user-generated traffic. Second, we design and deploy a prototype active measurement service for Android phones based on these key insights. Our analysis of 1650 measurements gathered from 12 volunteer devices shows that the system is able to obtain average throughput measurements that accurately quantify the performance experienced during times of active device and network usage.
Aaron Gember, Aditya Akella, Jeffrey Pang, Alexander Varshavsky, Ramón Cáceres
Internet Measurement Conference1
2011 REfactor-ing content overhearing to improve wireless performance
abstract
Many systems have leveraged the broadcast nature of wireless radios to improve wireless capacity and performance. While conventional approaches have focused on overhearing entire packets, recent designs have argued that focusing on overheard content may be more effective. Unfortunately, key design choices in these approaches limit them from fully leveraging the benefits of overhearing content. We propose a cleaner refactoring of functionality where-in overhearing is realized at the sub-packet payload level through the use of IP-layer redundancy elimination. We show that this dramatically improves the effectiveness of prior overhearing based approaches and enables new designs, e.g., enhanced network coding, where content overhearing can be more effectively integrated to improve performance. Realizing the benefits of IP-layer content overhearing requires us to overcome challenges arising from the probabilistic nature of wireless reception (which could lead to inconsistent state) and the limited resources on wireless devices. We overcome these challenges through careful data structure and wireless redundancy elimination designs. We evaluate the effectiveness of our system using experimentation on real traces. We find that our design is highly effective: e.g., it can improve goodput by nearly 25% and air time utilization by nearly 20%.
Shan-Hsiang Shen, Aaron Gember, Ashok Anand, Aditya Akella
MobiCom2
2011 A Comparative Study of Handheld and Non-handheld Traffic in Campus Wi-Fi Networks
Aaron Gember, Ashok Anand, Aditya Akella
PAM1