Csaba Györgyi

dblp:298/3266 · DBLP profile ↗
← Back
9ranked-venue papers
6as first author
9since 2021 · last 2024
0000-0002-8083-3277ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 4 · 3 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 SyRep: Efficient Synthesis and Repair of Fast Re-Route Forwarding Tables for Resilient Networks
abstract
In modern communication networks with stringent dependability requirements, local fast re-routing (FRR) is essential for a quick response to link failures. Configuring FRR for multiple failures is, however, challenging since a router's forwarding table may take into account only the failed links directly incident to it. We propose SyRep, an efficient method to repair and synthesize resilient FRR forwarding tables. At the heart of SyRep lies a method which identifies and removes ill-defined routing entries and employs symbolic binary decision diagram (BDD) technology to automatically replace the removed entries with correct values. SyRep cannot only be used to efficiently repair existing forwarding tables, but also to synthesize new tables from scratch, using an efficient hybrid approach: by first using fast heuristics that provide close-to-resilient routing tables and then quickly repair the ill-defined entries. We present such a fast heuristic based on novel structural reduction rules and our empirical evaluation shows that SyRep is up to three orders of magnitude faster compared to the state-of-the-art.
Csaba Györgyi, Kim G. Larsen, Stefan Schmid 0001, Jirí Srba
DSN1
2024 SyPer: Synthesis of Perfectly Resilient Local Fast Re-Routing Rules for Highly Dependable Networks
abstract
Modern communication networks support local fast re-routing (FRR) to quickly react to link failures. However, configuring such FRR mechanisms is challenging as the rules have to be defined ahead of time, without knowledge of the failures, and can depend only on local decisions made by the nodes incident to a failed link. Designing failover protection against multiple link failures is particularly difficult. We present a novel synthesis approach which addresses this challenge by generating FRR rules in an automated and provably correct manner. Our network model assumes that each node maintains a prioritised list of backup links (a.k.a. skipping forwarding)—an FRR method that allows for a memory-efficient deployment. We study the theoretical properties of the model and implement a synthesis method in our tool SyPer that aims to provide perfect resilience: if there are up to k link failures, we can always route traffic between any two nodes as long as they are still connected in the underlying physical network. To this end, SyPer focuses on the synthesis of efficient forwarding rules using the BDD (binary decision diagram) methodology and our empirical evaluation shows that SyPer is feasible, and can synthesize robust network configuration in realistic settings.
Csaba Györgyi, Kim G. Larsen, Stefan Schmid 0001, Jirí Srba
INFOCOM1
2024 Extensible FRER Security Testbed in a Box
abstract
Time-Sensitive Networking (TSN) is expected to provide reliable, low-latency communication for critical systems. Leveraging the Frame Replication and Elimination for Reliability (FRER) protocol, it protects against packet loss by replicating individual packets and delivering them on disjoint forwarding paths. FRER does not contain any in-built security solutions, and several FRER-related security vulnerabilities have recently been identified that could undermine TSN’s ultimate goal of providing extreme reliability. In this paper, we introduce a comprehensive security-focused testbed for analyzing FRER vulnerabilities. Our self-contained setup employs open and adaptable components, runnable on a single server, ensuring flexibility and accessibility. Leveraging eBPF/XDP, it efficiently implements FRER’s data plane functionalities, accommodating both fast-path and slow-path attacks. Parameters like delay, jitter, loss rate, and bandwidth are easily customizable. We validate the testbed’s effectiveness with various attack scenarios.
Károly Kecskeméti, Csaba Györgyi, Peter Vörös, Géza Szabó, Sándor Laki
NetSoft2
2023 In-Network Quality Control of IP Camera Streams
abstract
Manufacturing processes are often monitored by IP cameras. The generated video streams can be transferred via a wireless link to be processed and used by remote industrial controllers that manage and configure the industrial task in real-time. However, the link has limited bandwidth and is not capable of transmitting the aggregated traffic of all the IP cameras. Moreover, the platform provider of the remote controller (e.g., cloud) might charge extra fees for high volumes of network traffic. To optimize the data transport, we propose an in-network video quality control method for IP camera streams that drops non-essential frames from temporally irrelevant IP camera streams even when bandwidth is available. Our solution introduces a high-level API through which the operator can define which camera streams are needed with high quality at which actuator positions/states of the industrial process. Our method assumes an aggregation point that monitors the actuators' states and reduces the quality of camera streams that are not important for the control process, selectively dropping a set of video frames. We have implemented a P4-based prototype of the aggregation point and show that the remote controller can be fed with high-quality video streams while meeting bandwidth limitations and potentially saving data transfer costs without modifying the end-points.
Csaba Györgyi, Károly Kecskeméti, Peter Vörös, Sándor Laki, Géza Szabó
MobiHoc1
2023 In-Network Security Applications with P4RROT
abstract
Computer networks have become a key infrastructure for many different business domains. Ensuring the security of such interoperable systems is essential in many areas. The emergence of in-network computing and data plane programmability has opened the door to novel security approaches. Although the logic behind most novel solutions is simple, their implementation in P4 is often complex for a non-domain expert or requires problem-specific languages and code generators. Existing in-network approaches only solve specific subproblems and are not general purpose. In this paper, we show how the open-source P4 code generator called P4RROT can simplify the implementation of various in-network security applications. To demonstrate its applicability, we reproduce three recent P4-based security methods. During the implementation, we extended P4RROT with new primitives needed for such applications and also added support for Intel Tofino ASICs. The complexity of the corresponding P4RROT codes is a magnitude lower than the investigated original P4 programs.
Károly Kecskeméti, Csaba Györgyi, Peter Vörös, Sándor Laki
MobiHoc2
2023 Toward Highly Reliable Programmable Data Planes: Verification of P4 Code Generation
abstract
Data plane programming gained much attention in the past years, having a fast-growing community both in academia and industry. Many tools have emerged to simplify and/or help the development of reliable data plane programs, including fuzzing, formal verification, and different code generators. However, even the tools themselves must be verified to meet the most stringent dependability requirements. In this paper, we investigate various tools and methods to verify code generators leveraging P4 through the example of P4RROT (an open source code generator focusing on the application layer). We show that our approach is efficient and can indeed successfully find bugs. We identify two bugs and propose reusable ideas, such as the use of ghost code.
Csaba Györgyi, Sándor Laki, Stefan Schmid 0001
NetSoft1
2022 NETREACT: Distributed Event Detection in Sensor Data Streams with Disaggregated Packet Processing Pipelines
abstract
A new phenomenon called in-network computing has recently emerged with the aim of offloading calculations beyond the traditional task of packet forwarding to network switches. One of the most studied in-network computing applications is processing of sensor data streams. Existing works such as FastReact focus on solving this problem using flexible SmartNICs. In this paper, we propose NETREACT: an improved ASIC-oriented design for distributed event detection in sensor data streams to achieve a disaggregated processing pipeline. In contrast to existing approaches, NETREACT distributes the event detection task among a set of switches while leveraging the capabilities of the Intel Tofino platform in terms of boosting throughput and reducing latency. The proposed event-rule disaggregation method has the advantage of overcoming the hardware resource constraints and improving the overall network performance.
Csaba Györgyi, Károly Kecskeméti, Hiba Mallouhi, Peter Vörös, Sándor Laki
NetSoft1
2022 In-Network Velocity Control of Industrial Robot Arms
Sándor Laki, Csaba Györgyi, József Peto, Peter Vörös, Géza Szabó
NSDI2
2021 In-network Solution for Network Traffic Reduction in Industrial Data Communication
abstract
Industrial networks rely on standard real-time communication protocols like ProfiNet. These protocols are used for cyclic data exchange between IO devices and controllers. Since continuous monitoring of IO devices is important, a large number of data packets can be observed in such field networks between the IO devices and controllers. Each IO device cyclically reports its data or internal state to a controller at a predefined frequency. However, the reported data of most IO devices are not changing all the time, and thus the same bytes are transmitted multiple times. The majority of data packets is only used for checking the availability of such devices. In this paper, we consider an industrial environment where IO devices are located in an industrial site while controllers are running remotely (e.g., a software PLC in a private or edge cloud), and there is a radio link (e.g., 5G radio) between the two sides. We propose an in-network traffic reduction method that filters out the unnecessary data traffic at the two ends of the radio link, detects failure of devices and the radio link fast, and does not require any modification in the IO devices and controllers. Our solution is based on the cooperation of two P4-programmable networking elements deployed at the two sides of the radio link. Our preliminary measurements with P4-programmable hardware switches and emulated ProfiNet devices show that the method can significantly reduce the load on the radio link, while it could seamlessly be deployed in existing industrial environments.
Csaba Györgyi, Károly Kecskeméti, Peter Vörös, Géza Szabó, Sándor Laki
NetSoft1