Laurent Vanbever

dblp:51/7546 · DBLP profile ↗
← Back
80ranked-venue papers
4as first author
31since 2021 · last 2026
0000-0003-1455-4381ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 64 · 4 first-author · 24 since 2021Security and privacy · 8 · 3 since 2021Systems, architecture and hardware · 3 · 2 since 2021Software engineering, systems software and programming languages · 3Theory of computation · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Slow-And-Wide Transceivers Shouldn't Be Color Blind
abstract
Modern AI interconnects face hard trade-offs: copper links are efficient but have a short reach, optical transceivers are long-reach but more costly and energy-hungry. Similar trade-offs occur in the switching domain: packet switching is flexible but power-hungry, while circuit switching is efficient but coarse-grained. Recently, slow-and-wide transceivers have closed the gap between copper and traditional optics by exposing many low-rate optical channels, but limit them to a single logical point-to-point link.
Lukas Röllin, Sushovan Das, Benjamin Hoffman, Laurent Vanbever
SIGCOMM4
2026 All But Regular: Revisiting the Starlink Constellation
abstract
Prior work on LEO satellite networks focuses on regular constellations and grid-like topologies. Using existing Starlink satellite data, we uncover and systematically characterize the constellation's irregularities at multiple granularities, including shell distribution, orbital spacing, intra-orbit satellite placement, and hardware heterogeneity. To expose the actual impact of these irregularities, we try and superimpose grid-like topologies onto them, and study the impact of doing so. Our simulations show that forcing regular topologies on irregular constellations significantly affects routing and network performance, revealing a fundamental mismatch between idealized models and real deployments. Motivated by these findings, we outline future directions, including irregularity-aware topologies, systems and perspectives.
Pietro Ronchetti, Sushovan Das, Laurent Vanbever, Stefano Vissicchio
SIGCOMM3
2026 When static verification is not enough: revealing BGP bugs at runtime
Pietro Ronchetti, Tibor Schneider, Laurent Vanbever
SIGCOMM3
2026 Ampel: Scheduling at the Network Cut in ML Training
abstract
The size and communication patterns of modern ML training workloads place significant strain on datacenter fabrics. When bandwidth demand exceeds capacity, flows experience slowdowns and iteration time grows larger. Fine-grained load-balancing such as packet spraying cannot fully resolve this issue, yet it can shift the bottleneck from individual links to groups of links partitioning the network. In this work, we present Ampel: a system to schedule ML training flows at the network cuts. It leverages packet-spraying's ability to spread traffic evenly across all available paths to simplify the view of the topology into one only containing potential bottlenecks, and then bridges this new simplified model with past work on coflow scheduling. Our simulated experiments show that Ampel can reduce average training iteration time by up to 18% compared to state-of-the-art ML schedulers.
Valerio Torsiello, Ayush Mishra, Sushovan Das, Lukas Röllin, Tommaso Bonato, Torsten Hoefler, Laurent Vanbever
SIGCOMM7
2025 It Is Time to Address Network Power Proportionality
abstract
In recent years, networking hardware development has primarily focused on speed rather than power efficiency. By contrast, computing hardware has received a lot more attention given its dominant power footprint, especially in machine-learning (ML) data centers. With faster networks, we spend less time communicating and get more useful work out of the (increasingly expensive) computing hardware. But, the faster the network, the more time it idles and the worse its energy efficiency, which is magnified by the notorious lack of power proportionality of networking equipment.
Lukas Röllin, Romain Jacob, Laurent Vanbever
HotNets3
2025 Uncovering Hidden Proxy Smart Contracts for Finding Collision Vulnerabilities in Ethereum
abstract
The proxy design pattern allows Ethereum smart contracts to be simultaneously immutable and upgradeable, in which an original contract is split into a proxy contract containing the data storage and a logic contract containing the implementation logic. This architecture is known to have security issues, namely function collisions and storage collisions between the proxy and logic contracts, and has been exploited in real-world incidents to steal users’ millions of dollars worth of digital assets. In response to this concern, several previous works have sought to identify proxy contracts in Ethereum and detect their collisions. However, they all fell short due to their limited coverage, often restricting analysis to only contracts with available source code or past transactions.To bridge this gap, we present Proxion, an automated cross-contract analyzer that identifies all proxy smart contracts and their collisions in Ethereum. What sets Proxion apart is its ability to analyze hidden smart contracts that lack both source code and past transactions. Equipped with various techniques to enhance efficiency and accuracy, Proxion outperforms the state-of-the-art tools, notably identifying millions more proxy contracts and thousands of unreported collisions. We apply Proxion to analyze over 36 million alive contracts from 2015 to 2023, revealing that 54.2% of them are proxy contracts, and about 1.5 million contracts exhibit at least one collision issue.
Cheng-Kang Chen, Wen-Yi Chu, Muoi Tran, Laurent Vanbever, Hsu-Chun Hsiao
ICDCS4
2025 Guided Exploration of Control-Plane Routing States
abstract
In recent years, significant progress has been made towards scalable network control-plane verification. Yet, operators are still hesitant to deploy such systems. We argue that this reluctance is in part due to a semantic gap between operators reasoning about routing states and verifiers exploring the space of environments. Indeed, operators express the specification in terms of behavior of routing states, while verifiers usually rely on solvers to find specific environments that violate the specification. This semantic gap prevents users from guiding these solvers to directly explore routing states that violate the specification, or to search for states that are most relevant or likely.In this paper, we present a new approach for flexible control-plane verification. Instead of relying on rigid off-the-shelf solvers, we design a novel backtracking algorithm to directly explore the space of routing states. This enables users to guide the exploration according to the specification and domain-specific knowledge from operators. This algorithm paves the way for novel use cases, ranging from finding relevant (e.g., likely) counterexamples to performing verification of probabilistic specifications.
Tibor Schneider, Jean Mégret, Laurent Vanbever
ICNP3
2025 Fantastic Joules and Where to Find Them. Modeling and Optimizing Router Energy Demand
abstract
Reducing our society's energy demand is critical to address the sustainability challenge. While the Internet currently accounts for 1–-1.5% of global electricity consumption and continues to grow, the energy demands of one of its core components---routers---remain poorly understood. The available power data is limited and not fine-grained enough, offering little actionable insight into strategies for effectively reducing the Internet's energy consumption.
Romain Jacob, Lukas Röllin, Jackie Lim, Jonathan Chung 0006, Maurice Béhanzin, Weiran Wang 0006, Andreas Hunziker, Theodor Moroianu, Seyedali Tabaeiaghdaei, Adrian Perrig, Laurent Vanbever
IMC11
2025 Everything Matters in Programmable Packet Scheduling
Albert Gran Alcoz, Balázs Vass, Pooria Namyar, Behnaz Arzani, Gábor Rétvári, Laurent Vanbever
NSDI6
2025 Verifying maximum link loads in a changing world
Tibor Schneider, Stefano Vissicchio, Laurent Vanbever
NSDI3
2024 What is the next hop to more granular routing models?
abstract
Despite its widespread use, the "Gao-Rexford" model has long been recognized for its limitations in accurately capturing Internet routing behavior. However, the root causes of these limitations remain poorly understood, due to the lack of ground truth data. We address this by systematically analyzing inference techniques against generated topologies.
Ege Cem Kirci, Valerio Torsiello, Laurent Vanbever
HotNets3
2024 Routing Attacks on Cryptocurrency Mining Pools
abstract
Mining pools have been the driving force for ensuring the security of multiple proof-of-work (PoW) cryptocurrencies. Under the de facto protocol Stratum, pools allow miners to collaborate, discover new blocks, and earn rewards collectively. Recently, the blockchain community has been promoting the adoption of a more secure Stratum protocol known as Stratum V2. In this paper, we introduce Erosion, a novel network-level attack that applies to both Stratum and Stratum V2 protocols. The essence of the Erosion attack lies in its ability to disrupt connections between miners and a targeted mining pool, significantly impairing the miners’ contributed PoWs and reducing the victim’s mining power. We also discover a vulnerability in the Stratum V2 protocol that allows the adversary to persistently disrupt a connection by tampering with a single packet, thus enhancing the attack’s stealthiness. Our survey shows that the Erosion adversary can readily execute attacks against a significant majority (e.g., 91%) of mining pools across the top ten cryptocurrencies. We also observe an extreme mining centralization that enables Erosion adversaries to simultaneously target multiple pools and cryptocurrencies. Furthermore, our focused evaluation of pooled mining in Bitcoin reveals that thousands of different adversaries can gain control over the majority of Bitcoin mining power, with one potentially malicious Autonomous System capable of taking down 96% of the total mining power.
Muoi Tran, Theo von Arx, Laurent Vanbever
SP3
2024 Canary: Congestion-aware in-network allreduce using dynamic trees
abstract
The allreduce operation is an essential building block for many distributed applications, ranging from the training of deep learning models to scientific computing. In an allreduce operation, data from multiple hosts is aggregated together and then broadcasted to each host participating in the operation. Allreduce performance can be improved by a factor of two by aggregating the data directly in the network. Switches aggregate data coming from multiple ports before forwarding the partially aggregated result to the next hop. In all existing solutions, each switch needs to know the ports from which it will receive the data to aggregate. However, this forces packets to traverse a predefined set of switches, making these solutions prone to congestion. For this reason, we design Canary, the first congestion-aware in-network allreduce algorithm. Canary uses load balancing algorithms to forward packets on the least congested paths. Because switches do not know from which ports they will receive the data to aggregate, they use timeouts to aggregate the data in a best-effort way. We develop a P4 Canary prototype and evaluate it on a Tofino switch. We then validate Canary through simulations on large networks, showing performance improvements up to 40% compared to the state-of-the-art.
Daniele De Sensi, Edgar Costa Molero, Salvatore Di Girolamo, Laurent Vanbever, Torsten Hoefler
Future Gener. Comput. Syst.4
2023 Revelio: A Network-Level Privacy Attack in the Lightning Network
abstract
The Lightning Network (LN) is a widely-adopted off-chain protocol that not only addresses Bitcoin’s scaling problem but also enables anonymous payments. Prior attacks have shown that an adversary controlling several peers at the central position of the network (e.g., by hijacking payment routes) can deanonymize such payments. However, these attacks are highly observable or require many parties to collude.This paper presents Revelio, a stealthier, passive network-level privacy attack against LN that exploits its joint centralization at the application and the network layers. Indeed, network-level adversaries can see most of the LN traffic (e.g., five autonomous systems can see up to 80 % of all observable communication channels) despite the encrypted communication between LN nodes and the widespread usage of Tor. This comprehensive view allows Revelio adversaries not only to estimate the payment amount but also to effectively reduce the anonymity size of its endpoints. We show that the Revelio attack is practical: it perfectly deanonymizes the senders or the receiver in almost one-third of tested payments in today’s LN and underlying network topologies.
Theo von Arx, Muoi Tran, Laurent Vanbever
EuroS&P3
2023 QVISOR: Virtualizing Packet Scheduling Policies
abstract
The concept of programmable packet scheduling has been recently introduced, enabling the programming of scheduling algorithms into existing data planes without requiring new hardware designs. Notably, several programmable schedulers have been proposed, which are capable of running directly on existing commodity switches. Unfortunately, though, their focus has been limited to single-tenant traffic scheduling: i.e., scheduling all incoming traffic following one single scheduling policy (e.g., pFabric to minimize flow completion times).
Albert Gran Alcoz, Laurent Vanbever
HotNets2
2023 Enhancing Global Network Monitoring with Magnifier
Tobias Bühler, Romain Jacob, Ingmar Poese, Laurent Vanbever
NSDI4
2023 xBGP: Faster Innovation in Routing Protocols
Thomas Wirtgen, Tom Rousseaux, Quentin De Coninck, Nicolas Rybowski, Randy Bush, Laurent Vanbever, Axel Legay, Olivier Bonaventure
NSDI6
2023 Poster: Learning distributions to detect anomalies using all the network traffic
abstract
Anomaly detection is an essential building block of many applications, including DDoS detection, root cause analysis, traffic estimation, and change detection. A vital part of detecting anomalies is establishing a sense of normality, e.g., by learning distributions for various features from benign traffic. Learning these distributions in the control plane requires coping with the limited visibility of sampling; learning distributions in the data plane requires relying on simplistic techniques because of hardware constraints.
Alexander Dietmüller, Georgia Fragkouli, Laurent Vanbever
SIGCOMM3
2023 Taming the transient while reconfiguring BGP
abstract
BGP reconfigurations are a daily occurrence for most network operators, especially in large networks. Yet, performing safe and robust BGP reconfiguration changes is still an open problem. Few BGP reconfiguration techniques exist, and they are either (i) unsafe, because they ignore transient states, which can easily lead to invariant violations; or (ii) impractical, as they duplicate the entire routing and forwarding states, and require special hardware.
Tibor Schneider, Roland Schmid, Stefano Vissicchio, Laurent Vanbever
SIGCOMM4
2023 FnF-BFT: A BFT Protocol with Provable Performance Under Attack
Zeta Avarikioti, Lioba Heimbach, Roland Schmid, Laurent Vanbever, Roger Wattenhofer, Patrick Wintermeyer
SIROCCO4
2022 Generating representative, live network traffic out of millions of code repositories
abstract
In theory, any network operator, developer, or vendor should have access to large amounts of live network traffic for testing their solutions. In practice, though, that is not the case. Network actors instead have to use packet traces or synthetic traffic, which is highly suboptimal: today's generated traffic is unrealistic. We propose a system for generating live application traffic leveraging massive codebases such as GitHub.
Tobias Bühler, Roland Schmid, Sandro Lutz, Laurent Vanbever
HotNets4
2022 A new hope for network model generalization
abstract
Generalizing machine learning (ML) models for network traffic dynamics tends to be considered a lost cause. Hence for every new task, we design new models and train them on model-specific datasets closely mimicking the deployment environments. Yet, an ML architecture called Transformer has enabled previously unimaginable generalization in other domains. Nowadays, one can download a model pre-trained on massive datasets and only fine-tune it for a specific task and context with comparatively little time and data. These fine-tuned models are now state-of-the-art for many benchmarks.
Alexander Dietmüller, Siddhant Ray, Romain Jacob, Laurent Vanbever
HotNets4
2022 On the Complexity of Network-Wide Configuration Synthesis
abstract
Configuration Synthesis promises to increase automation in network hardware configuration but is generally assumed to constitute a computationally hard problem. We conduct a formal analysis of the computational complexity of network-wide Configuration Synthesis to establish this claim formally. To that end, we consider Configuration Synthesis as a decision problem, whether or not the selected routing protocol(s) can implement a given set of forwarding properties. We find the complexity of Configuration Synthesis heavily depends on the combination of the forwarding properties that need to be implemented in the network, as well as the employed routing protocol(s). Our analysis encompasses different forwarding properties that can be encoded as path constraints, and any combination of distributed destination-based hop-by-hop routing protocols. Many of these combinations yield NP-hard Configuration Synthesis problems; in particular, we show that the satisfiability of a set of arbitrary waypoints for any hop-by-hop routing protocol is NP-complete. Other combinations, however, show potential for efficient, scalable Configuration Synthesis.
Tibor Schneider, Roland Schmid, Laurent Vanbever
ICNP3
2022 "Is my internet down?": sifting through user-affecting outages with Google trends
abstract
What are the worst outages for Internet users? How long do they last, and how wide are they? Such questions are hard to answer via traditional outage detection and analysis techniques, as they conventionally rely on network-level signals and do not necessarily represent users' perceptions of connectivity.
Ege Cem Kirci, Martin Vahlensieck, Laurent Vanbever
IMC3
2022 ditto: WAN Traffic Obfuscation at Line Rate
Roland Meier, Vincent Lenders, Laurent Vanbever
NDSS3
2022 Learning to Configure Computer Networks with Neural Algorithmic Reasoning
abstract
We present a new method for scaling automatic configuration of computer networks. The key idea is to relax the computationally hard search problem of finding a configuration that satisfies a given specification into an approximate objective amenable to learning-based techniques. Based on this idea, we train a neural algorithmic model which learns to generate configurations likely to (fully or partially) satisfy a given specification under existing routing protocols. By relaxing the rigid satisfaction guarantees, our approach (i) enables greater flexibility: it is protocol-agnostic, enables cross-protocol reasoning, and does not depend on hardcoded rules; and (ii) finds configurations for much larger computer networks than previously possible. Our learned synthesizer is up to 490x faster than state-of-the-art SMT-based methods, while producing configurations which on average satisfy more than 93% of the provided requirements.
Luca Beurer-Kellner, Martin T. Vechev, Laurent Vanbever, Petar Velickovic
NeurIPS3
2022 ABM: active buffer management in datacenters
abstract
Today's network devices share buffer across queues to avoid drops during transient congestion and absorb bursts. As the buffer-per-bandwidth-unit in datacenter decreases, the need for optimal buffer utilization becomes more pressing. Typical devices use a hierarchical packet admission control scheme: First, a Buffer Management (BM) scheme decides the maximum length per queue at the device level and then an Active Queue Management (AQM) scheme decides which packets will be admitted at the queue level. Unfortunately, the lack of cooperation between the two control schemes leads to (i) harmful interference across queues, due to the lack of isolation; (ii) increased queueing delay, due to the obliviousness to the per-queue drain time; and (iii) thus unpredictable burst tolerance. To overcome these limitations, we propose ABM, Active Buffer Management which incorporates insights from both BM and AQM. Concretely, ABM accounts for both total buffer occupancy (typically used by BM) and queue drain time (typically used by AQM). We analytically prove that ABM provides isolation, bounded buffer drain time and achieves predictable burst tolerance without sacrificing throughput. We empirically find that ABM improves the 99th percentile FCT for short flows by up to 94% compared to the state-of-the-art buffer management. We further show that ABM improves the performance of advanced datacenter transport protocols in terms of FCT by up to 76% compared to DCTCP, TIMELY and PowerTCP under bursty workloads even at moderate load conditions.
Vamsi Addanki, Maria Apostolaki, Manya Ghobadi, Stefan Schmid 0001, Laurent Vanbever
SIGCOMM5
2022 Aggregate-based congestion control for pulse-wave DDoS defense
abstract
Pulse-wave DDoS attacks are a new type of volumetric attack formed by short, high-rate traffic pulses. Such attacks target the Achilles' heel of state-of-the-art DDoS defenses: their reaction time. By continuously adapting their attack vectors, pulse-wave attacks manage to render existing defenses ineffective.
Albert Gran Alcoz, Martin Strohmeier, Vincent Lenders, Laurent Vanbever
SIGCOMM4
2022 FAst in-network GraY failure detection for ISPs
abstract
Avoiding packet loss is crucial for ISPs. Unfortunately, malfunctioning hardware at ISPs can cause long-lasting packet drops, also known as gray failures, which are undetectable by existing monitoring tools.
Edgar Costa Molero, Stefano Vissicchio, Laurent Vanbever
SIGCOMM3
2021 Metha: Network Verifiers Need To Be Correct Too!
Rüdiger Birkner, Tobias Brodmann, Petar Tsankov, Laurent Vanbever, Martin T. Vechev
NSDI4
2021 Snowcap: synthesizing network-wide configuration updates
abstract
Large-scale reconfiguration campaigns tend to be nerve-racking for network operators as they can lead to significant network downtimes, decreased performance, and policy violations. Unfortunately, existing reconfiguration frameworks often fall short in practice as they either only support a small set of reconfiguration scenarios or simply do not scale.
Tibor Schneider, Rüdiger Birkner, Laurent Vanbever
SIGCOMM3
2020 P2GO: P4 Profile-Guided Optimizations
abstract
Programmable devices allow the operator to specify the data-plane behavior of a network device in a high-level language such as P4. The compiler then maps the P4 program to the hardware after applying a set of optimizations to minimize resource utilization. Yet, the lack of context restricts the compiler to conservatively account for all possible inputs -- including unrealistic or infrequent ones -- leading to sub-optimal use of the resources or even compilation failures. To address this inefficiency, we propose that the compiler leverages insights from actual traffic traces, effectively unlocking a broader spectrum of possible optimizations. We present a system working alongside the compiler that uses traffic-awareness to reduce the allocated resources of a P4 program by: (i) removing dependencies that do not manifest; (ii) adjusting table and register sizes to reduce the pipeline length; and (iii) offloading parts of the program that are rarely used to the controller. Our prototype implementation on the Tofino switch automatically profiles the P4 program, detects opportunities and performs optimizations to improve the pipeline efficiency. Our work showcases the potential benefit of applying profiling techniques used to compile general-purpose languages to compiling P4 programs.
Patrick Wintermeyer, Maria Apostolaki, Alexander Dietmüller, Laurent Vanbever
HotNets4
2020 xBGP: When You Can't Wait for the IETF and Vendors
abstract
Thanks to the standardization of routing protocols such as BGP, OSPF or IS-IS, Internet Service Providers (ISP) and enterprise networks can deploy routers from various vendors. This prevents them from vendor-lockin problems. Unfortunately, this also slows innovation since any new feature must be standardized and implemented by all vendors before being deployed.
Thomas Wirtgen, Quentin De Coninck, Randy Bush, Laurent Vanbever, Olivier Bonaventure
HotNets4
2020 SP-PIFO: Approximating Push-In First-Out Behaviors using Strict-Priority Queues
Albert Gran Alcoz, Alexander Dietmüller, Laurent Vanbever
NSDI3
2020 Config2Spec: Mining Network Specifications from Network Configurations
Rüdiger Birkner, Dana Drachsler-Cohen, Laurent Vanbever, Martin T. Vechev
NSDI3
2020 Probabilistic Verification of Network Configurations
abstract
Not all important network properties need to be enforced all the time. Often, what matters instead is the fraction of time / probability these properties hold. Computing the probability of a property in a network relying on complex inter-dependent routing protocols is challenging and requires determining all failure scenarios for which the property is violated. Doing so at scale and accurately goes beyond the capabilities of current network analyzers.
Samuel Steffen, Timon Gehr, Petar Tsankov, Laurent Vanbever, Martin T. Vechev
SIGCOMM4
2019 (Self) Driving Under the Influence: Intoxicating Adversarial Network Inputs
abstract
Traditional network control planes can be slow and require manual tinkering from operators to change their behavior. There is thus great interest in a faster, data-driven approach that uses signals from real-time traffic instead. However, the promise of fast and automatic reaction to data comes with new risks: malicious inputs designed towards negative outcomes for the network, service providers, users, and operators.
Roland Meier, Thomas Holterbach, Stephan Keck, Matthias Stähli, Vincent Lenders, Ankit Singla, Laurent Vanbever
HotNets7
2019 SABRE: Protecting Bitcoin against Routing Attacks
Maria Apostolaki, Gian Marti, Laurent Vanbever
NDSS4
2019 Latency and Consistent Flow Migration: Relax for Lossless Updates
abstract
Consistency in network updates is a nascent research area, especially in the context of traffic engineering or Software Defined Networks. Various approaches have been proposed and implemented in the problem space of flow migration and congestion, primarily focusing on different flows not breaking the bandwidth capacities of the used links during updates. However, current network update techniques overlook the effect of flows congesting their own path during a network update due to latency on the links. Furthermore, while congestion will be resolved eventually after the network update, the buffers of the affected routers can be filled for a long time period, leading to the following paradox: a flow is moved to a path with less latency, but the latency stays the same! As flows are often migrated because of latency concerns, this is highly undesirable. We show that these effects occur already in a small topology in practice, causing packet loss due to overfull buffers. Furthermore, we prove that finding a lossless flow migration is NP-hard, already for a single (splittable) flow on directed acyclic graphs. Nonetheless, we can relax latency requirements to still obtain lossless flow migration. To this end, we show how to adapt current systems such as SWAN or Dionysus [SIGCOMM'13/'14], also developing our own polynomial time schedule algorithm, and discussing future consistent flow migration technique adaptations.
Klaus-Tycho Förster, Laurent Vanbever, Roger Wattenhofer
Networking2
2019 Blink: Fast Connectivity Recovery Entirely in the Data Plane
Thomas Holterbach, Edgar Costa Molero, Maria Apostolaki, Alberto Dainotti, Stefano Vissicchio, Laurent Vanbever
NSDI6
2018 Hardware-Accelerated Network Control Planes
abstract
One design principle of modern network architecture seems to be set in stone: a software-based control plane drives a hardware- or software-based data plane. We argue that it is time to revisit this principle after the advent of programmable switch ASICs which can run complex logic at line rate.
Edgar Costa Molero, Stefano Vissicchio, Laurent Vanbever
HotNets3
2018 Net2Text: Query-Guided Summarization of Network Forwarding Behaviors
Rüdiger Birkner, Dana Drachsler-Cohen, Laurent Vanbever, Martin T. Vechev
NSDI3
2018 NetComplete: Practical Network-Wide Configuration Synthesis with Autocompletion
Ahmed El-Hassany, Petar Tsankov, Laurent Vanbever, Martin T. Vechev
NSDI3
2018 Stroboscope: Declarative Network Monitoring on a Budget
Olivier Tilmans, Tobias Bühler, Ingmar Poese, Stefano Vissicchio, Laurent Vanbever
NSDI5
2018 Bayonet: probabilistic inference for networks
abstract
Network operators often need to ensure that important probabilistic properties are met, such as that the probability of network congestion is below a certain threshold. Ensuring such properties is challenging and requires both a suitable language for probabilistic networks and an automated procedure for answering probabilistic inference queries.
Timon Gehr, Sasa Misailovic, Petar Tsankov, Laurent Vanbever, Pascal Wiesmann, Martin T. Vechev
PLDI4
2018 NetHide: Secure and Practical Network Topology Obfuscation
Roland Meier, Petar Tsankov, Vincent Lenders, Laurent Vanbever, Martin T. Vechev
USENIX Security Symposium4
2017 Network-Wide Configuration Synthesis
Ahmed El-Hassany, Petar Tsankov, Laurent Vanbever, Martin T. Vechev
CAV (2)3
2017 Unsupervised Detection of APT C&C Channels using Web Request Graphs
Pavlos Lamprakis, Ruggiero Dargenio, David Gugelmann, Vincent Lenders, Markus Happe, Laurent Vanbever
DIMVA6
2017 Integrating Verification and Repair into the Control Plane
abstract
Network verification has made great progress recently, yet existing solutions are limited in their ability to handle specific protocols or implementation quirks or to diagnose and repair the cause of policy violations. In this positioning paper, we examine whether we can achieve the best of both worlds: full coverage of control plane protocols and decision processes combined with the ability to diagnose and repair the cause of violations. To this end, we leverage the happens-before relationships that exist between control plane I/Os (e.g., route advertisements and forwarding updates). These relationships allow us to identify when it is safe to employ a data plane verifier and track the root-cause of problematic forwarding updates. We show how we can capture errors before they are installed, automatically trace down the source of the error and roll-back the updates whenever possible.
Aaron Gember, Costin Raiciu, Laurent Vanbever
HotNets3
2017 SWIFT: Predictive Fast Reroute
abstract
Network operators often face the problem of remote outages in transit networks leading to significant (sometimes on the order of minutes) downtimes. The issue is that BGP, the Internet routing protocol, often converges slowly upon such outages, as large bursts of messages have to be processed and propagated router by router.
Thomas Holterbach, Stefano Vissicchio, Alberto Dainotti, Laurent Vanbever
SIGCOMM4
2017 Hijacking Bitcoin: Routing Attacks on Cryptocurrencies
abstract
As the most successful cryptocurrency to date, Bitcoin constitutes a target of choice for attackers. While many attack vectors have already been uncovered, one important vector has been left out though: attacking the currency via the Internet routing infrastructure itself. Indeed, by manipulating routing advertisements (BGP hijacks) or by naturally intercepting traffic, Autonomous Systems (ASes) can intercept and manipulate a large fraction of Bitcoin traffic. This paper presents the first taxonomy of routing attacks and their impact on Bitcoin, considering both small-scale attacks, targeting individual nodes, and large-scale attacks, targeting the network as a whole. While challenging, we show that two key properties make routing attacks practical: (i) the efficiency of routing manipulation; and (ii) the significant centralization of Bitcoin in terms of mining and routing. Specifically, we find that any network attacker can hijack few (<;100) BGP prefixes to isolate ~50% of the mining power-even when considering that mining pools are heavily multi-homed. We also show that on-path network attackers can considerably slow down block propagation by interfering with few key Bitcoin messages. We demonstrate the feasibility of each attack against the deployed Bitcoin software. We also quantify their effectiveness on the current Bitcoin topology using data collected from a Bitcoin supernode combined with BGP routing data. The potential damage to Bitcoin is worrying. By isolating parts of the network or delaying block propagation, attackers can cause a significant amount of mining power to be wasted, leading to revenue losses and enabling a wide range of exploits such as double spending. To prevent such effects in practice, we provide both short and long-term countermeasures, some of which can be deployed immediately.
Maria Apostolaki, Aviv Zohar, Laurent Vanbever
IEEE Symposium on Security and Privacy3
2017 Safe Update of Hybrid SDN Networks
abstract
The support for safe network updates, i.e., live modification of device behavior without service disruption, is a critical primitive for current and future networks. Several techniques have been proposed by previous works to implement such a primitive. Unfortunately, existing techniques are not generally applicable to any network architecture, and typically require high overhead (e.g., additional memory) to guarantee strong consistency (i.e., traversal of either initial or final paths, but never a mix of them) during the update. In this paper, we deeply study the problem of computing operational sequences to safely and quickly update arbitrary networks. We characterize cases, for which this computation is easy, and revisit previous algorithmic contributions in the new light of our theoretical findings. We also propose and thoroughly evaluate a generic sequence-computation approach, based on two new algorithms that we combine to overcome limitations of prior proposals. Our approach always finds an operational sequence that provably guarantees strong consistency throughout the update, with very limited overhead. Moreover, it can be applied to update networks running any combination of centralized and distributed control-planes, including different families of IGPs, OpenFlow or other SDN protocols, and hybrid SDN networks. Our approach therefore supports a large set of use cases, ranging from traffic engineering in IGP-only or SDN-only networks to incremental SDN roll-out and advanced requirements (e.g., per-flow path selection or dynamic network function virtualization) in partial SDN deployments.
Stefano Vissicchio, Laurent Vanbever, Luca Cittadini, Geoffrey G. Xie, Olivier Bonaventure
IEEE/ACM Trans. Netw.2
2016 ACM CoNEXT 2016 Student Workshop
abstract
The ACM CoNEXT 2016 Student Workshop is held in Irvine, California, USA on December 12, 2016 and co-located with the ACM 12th International Conference on emerging Networking Experiments and Technologies (CoNEXT 2016). The main objective of the workshop is to provide a platform for graduate students in the area of computer networks and communications to present their ongoing research efforts. The workshop is also a unique opportunity for students to network with other junior researchers as well as more experienced ones, receive constructive feedback, guidance, tips, and learn about cutting-edge research problems being tackled by the community. We have constructed an exciting program of 24 refereed presentations and posters, and an invited keynote talk (by Prof. Lixia Zhang, UCLA) that will give participating students an opportunity to hear from a senior researcher.
Rocky K. C. Chang, Hulya Seferoglu, Laurent Vanbever
CoNEXT3
2016 Mille-Feuille: Putting ISP traffic under the scalpel
abstract
For Internet Service Provider (ISP) operators, getting an accurate picture of how their network behaves is challenging. Given the traffic volumes that their networks carry and the impossibility to control end-hosts, ISP operators are typically forced to randomly sample traffic, and rely on aggregated statistics. This provides coarse-grained visibility, at a time resolution that is far from ideal (seconds or minutes). In this paper, we present Mille-Feuille, a novel monitoring architecture that provides fine-grained visibility over ISP traffic. Mille-Feuille schedules activation and deactivation of traffic-mirroring rules, that are then provisioned network-wide from a central location, within milliseconds. By doing so, Mille-Feuille combines the scalability of sampling with the visibility and controllability of traffic mirroring. As a result, it supports a set of monitoring primitives, ranging from checking key performance indicators (e.g., one-way delay) for single destinations to estimating traffic matrices in sub-seconds. Our preliminary measurements on existing routers confirm that Mille-Feuille is viable in practice.
Olivier Tilmans, Tobias Bühler, Stefano Vissicchio, Laurent Vanbever
HotNets4
2016 An Industrial-Scale Software Defined Internet Exchange Point
Arpit Gupta, Robert MacDavid, Rüdiger Birkner, Marco Canini, Nick Feamster, Jennifer Rexford, Laurent Vanbever
NSDI7
2016 SDNRacer: concurrency analysis for software-defined networks
abstract
Concurrency violations are an important source of bugs in Software-Defined Networks (SDN), often leading to policy or invariant violations. Unfortunately, concurrency violations are also notoriously difficult to avoid, detect and debug. This paper presents a novel approach and a tool, SDNRacer, for detecting concurrency violations of SDNs. Our approach is enabled by three key ingredients: (i) a precise happens- before model for SDNs that captures when events can happen concurrently; (ii) a set of sound, domain-specific filters that reduce reported violations by orders of magnitude, and; (iii) a sound and complete dynamic analyzer, based on the above, that can ensure the network is free of harmful errors such as data races and per-packet incoherence. We evaluated SDNRacer on several real-world OpenFlow controllers, running both reactive and proactive applications in large networks. We show that SDNRacer is practically effective: it quickly pinpoints harmful concurrency violations without overwhelming the user with false positives.
Ahmed El-Hassany, Jeremie Miserez, Pavol Bielik, Laurent Vanbever, Martin T. Vechev
PLDI4
2016 Fibbing in action: On-demand load-balancing for better video delivery
abstract
Video streaming, in conjunction with social networks, have given birth to a new traffic pattern over the Internet: transient, localized traffic surges, known as flash crowds. Traditional traffic-engineering methods can hardly cope with these surges, as they are unpredictable by nature. Consequently, networks either have to be over-provisioned, which is expensive and wastes resources, or risk to periodically incur congestion, which infuriates customers. This demonstration shows how Fibbing can improve network performance and preserve users’ quality of experience when accessing video streams, by implementing a fine-grained load-balancing service. This service leverages two unique features of Fibbing: programming per destination load-balancing and implementing uneven splitting ratios.
Olivier Tilmans, Stefano Vissicchio, Laurent Vanbever, Jennifer Rexford
SIGCOMM3
2016 An Industrial-Scale Software Defined Internet Exchange Point
Arpit Gupta, Robert MacDavid, Rüdiger Birkner, Marco Canini, Nick Feamster, Jennifer Rexford, Laurent Vanbever
USENIX ATC7
2016 Scaling the Internet Routing System Through Distributed Route Aggregation
abstract
The Internet routing system faces serious scalability challenges due to the growing number of IP prefixes that needs to be propagated throughout the network. Although IP prefixes are assigned hierarchically and roughly align with geographic regions, today's Border Gateway Protocol (BGP) and operational practices do not exploit opportunities to aggregate routing information. We present DRAGON, a distributed route-aggregation technique whereby nodes analyze BGP routes across different prefixes to determine which of them can be filtered while respecting the routing policies for forwarding data-packets. DRAGON works with BGP, can be deployed incrementally, and offers incentives for Autonomous Systems (ASs) to upgrade their router software. We illustrate the design of DRAGON through a number of examples, prove its properties while developing a theoretical model of route aggregation, and evaluate its performance. Our experiments with realistic AS-level topologies, assignments of IP prefixes, and routing policies show that DRAGON reduces the number of prefixes in each AS by at least 70% with minimal stretch in the lengths of AS-paths traversed by data packets.
João L. Sobrinho, Laurent Vanbever, Franck Le, André Sousa, Jennifer Rexford
IEEE/ACM Trans. Netw.2
2015 Destroying networks for fun (and profit)
abstract
Network failures are inevitable. Interfaces go down, devices crash and resources become exhausted. It is the responsibility of the control software to provide reliable services on top of unreliable components and throughout unpredictable events. Guaranteeing the correctness of the controller under all types of failures is therefore essential for network operations. Yet, this is also an almost impossible task due to the complexity of the control software, the underlying network, and the lack of precision in simulation tools.
Nick Shelly, Brendan Tschaen, Klaus-Tycho Förster, Michael Alan Chang, Theophilus Benson, Laurent Vanbever
HotNets6
2015 Quantifying Interference between Measurements on the RIPE Atlas Platform
abstract
Public measurement platforms composed of low-end hardware devices such as RIPE Atlas have gained significant traction in the research community. Such platforms are indeed particularly interesting as they provide Internet-wide measurement capabilities together with an ever growing set of measurement tools. To be scalable though, they allow for concurrent measurements between users. This paper answers a fundamental question for any platform user: Do measurements launched by others impact my results? If so, what can I do about it?
Thomas Holterbach, Cristel Pelsser, Randy Bush, Laurent Vanbever
Internet Measurement Conference4
2015 On the co-existence of distributed and centralized routing control-planes
abstract
Network operators can and do deploy multiple routing control-planes, e.g., by running different protocols or instances of the same protocol. With the rise of SDN, multiple control-planes are likely to become even more popular, e.g., to enable hybrid SDN or multi-controller deployments. Unfortunately, previous works do not apply to arbitrary combinations of centralized and distributed control-planes. In this paper, we develop a general theory for coexisting control-planes. We provide a novel, exhaustive classification of existing and future control-planes (e.g., OSPF, EIGRP, and Open-Flow) based on fundamental control-plane properties that we identify. Our properties are general enough to study centralized and distributed control-planes under a common framework. We show that multiple uncoordinated control-planes can cause forwarding anomalies whose type solely depends on the identified properties. To show the wide applicability of our framework, we leverage our theoretical insight to (i) provide sufficient conditions to avoid anomalies, (ii) propose configuration guidelines, and (iii) define a provably-safe procedure for reconfigurations from any (combination of) control-planes to any other. Finally, we discuss prominent consequences of our findings on the deployment of new paradigms (notably, SDN) and previous research works.
Stefano Vissicchio, Luca Cittadini, Olivier Bonaventure, Geoffrey G. Xie, Laurent Vanbever
INFOCOM5
2015 Supercharge me: Boost Router Convergence with SDN
abstract
By enabling logically-centralized and direct control of the forwarding behavior of a network, Software-Defined Networking (SDN) holds great promise in terms of improving network management, performance, and costs. Realizing this vision is challenging though as SDN proposals to date require substantial and expensive changes to the existing network architecture before the benefits can be realized. As a result, the number of SDN deployments has been rather limited in scope. To kickstart a wide-scale SDN deployment, there is a need for low-risk, high return solutions that solve a timely problem. As one possible solution, we show how we can significantly improve the performance of legacy IP routers, i.e. "supercharge" them, by combining them with SDN-enabled devices. In this abstract, we supercharge one particular aspect of the router performance: its convergence time after a link or a node failure.
Michael Alan Chang, Thomas Holterbach, Markus Happe, Laurent Vanbever
SIGCOMM4
2015 Chaos Monkey: Increasing SDN Reliability through Systematic Network Destruction
abstract
No abstract available.
Michael Alan Chang, Brendan Tschaen, Theophilus Benson, Laurent Vanbever
SIGCOMM4
2015 Central Control Over Distributed Routing
abstract
Centralizing routing decisions offers tremendous flexibility, but sacrifices the robustness of distributed protocols. In this paper, we present Fibbing, an architecture that achieves both flexibility and robustness through central control over distributed routing. Fibbing introduces fake nodes and links into an underlying link-state routing protocol, so that routers compute their own forwarding tables based on the augmented topology. Fibbing is expressive, and readily supports flexible load balancing, traffic engineering, and backup routes. Based on high-level forwarding requirements, the Fibbing controller computes a compact augmented topology and injects the fake components through standard routing-protocol messages. Fibbing works with any unmodified routers speaking OSPF. Our experiments also show that it can scale to large networks with many forwarding requirements, introduces minimal overhead, and quickly reacts to network and controller failures.
Stefano Vissicchio, Olivier Tilmans, Laurent Vanbever, Jennifer Rexford
SIGCOMM3
2015 RAPTOR: Routing Attacks on Privacy in Tor
Yixin Sun 0004, Anne Edmundson, Laurent Vanbever, Oscar Li, Jennifer Rexford, Mung Chiang, Prateek Mittal
USENIX Security Symposium3
2014 Distributed Route Aggregation on the Global Network
abstract
The Internet routing system faces serious scalability challenges, due to the growing number of IP prefixes it needs to propagate throughout the network. For example, the Internet suffered significant outages in August 2014 when the number of globally routable prefixes went past 512K, the default size of the forwarding tables in many older routers. Although IP prefixes are assigned hierarchically, and roughly align with geographic regions, today's Border Gateway Protocol (BGP) and operational practices do not exploit opportunities to aggregate routes. We present a distributed route-aggregation technique (called DRAGON) where nodes analyze BGP routes across different prefixes to determine which of them can be filtered while respecting the routing policies for forwarding data-packets. DRAGON works with BGP, can be deployed incrementally, and offers incentives for ASs to upgrade their router software. We present a theoretical model of route-aggregation, and the design and analysis of DRAGON. Our experiments with realistic assignments of IP prefixes, network topologies, and routing policies show that DRAGON reduces the number of prefixes in each AS by about 80% and significantly curtails the number of routes exchanged during transient periods of convergence.
João L. Sobrinho, Laurent Vanbever, Franck Le, Jennifer Rexford
CoNEXT2
2014 Anonymity on QuickSand: Using BGP to Compromise Tor
abstract
Anonymity systems like Tor are known to be vulnerable to malicious relay nodes. Another serious threat comes from the Autonomous Systems (ASes) that carry Tor traffic due to their powerful eavesdropping capabilities. Indeed, an AS (or set of colluding ASes) that lies between the client and the first relay, and between the last relay and the destination, can perform timing analysis to compromise user anonymity. In this paper, we show that AS-level adversaries are much more powerful than previously thought. First, routine BGP routing changes can significantly increase the number of ASes that can analyze a user's traffic successfully. Second, ASes can actively manipulate BGP announcements to put themselves on the paths to and from relay nodes. Third, an AS can perform timing analysis even when it sees only one direction of the traffic at both communication ends. Actually, asymmetric routing increases the fraction of ASes able to analyze a user's traffic. We present a preliminary evaluation of our attacks using measurements of BGP and Tor. Our findings motivate the design of approaches for anonymous communication that are resilient to AS-level adversaries.
Laurent Vanbever, Oscar Li, Jennifer Rexford, Prateek Mittal
HotNets1
2014 Sweet Little Lies: Fake Topologies for Flexible Routing
abstract
Link-state routing protocols (e.g., OSPF and IS-IS) are widely used because they are scalable, robust, and based on simple abstractions. Unfortunately, these protocols are also relatively inflexible, since they direct all traffic over shortest paths. In contrast, Software Defined Networking (SDN) offers fine-grained control over routing, at the expense of controller overhead, failover latency, and deployment challenges.
Stefano Vissicchio, Laurent Vanbever, Jennifer Rexford
HotNets2
2014 In-Band Update for Network Routing Policy Migration
abstract
Network operators often need to change their routing policy in response to network failures, new load balancing strategies, or stricter security requirements. While several recent works have aimed at solving this problem, they all assume that a fast and conveniently dimensioned out-of band network is available to communicate with any device. Unfortunately, such a parallel network is often not practical. This paper presents a technique for performing such updates in-band: it enables reconfiguration control messages to be sent directly within the fast production network. Performing such updates is hard because intermediate configurations can lock out the controller from devices before they are updated. Thus, updates have to be carefully sequenced. Our technique also minimizes the total update time by updating the network in parallel, whenever possible. Our technique takes into account in-band middle boxes, such as firewalls. We have implemented our framework using Integer Linear Programming, and experimentally validated it on problems of realistic scale.
Sharad Malik, Sanjai Narain, Laurent Vanbever
ICNP4
2014 Safe routing reconfigurations with route redistribution
abstract
Simultaneously providing flexibility, evolvability and correctness of routing is one of the basic and still unsolved problems in networking. Route redistribution provides a tool, used in many enterprise networks, to either partition a network into multiple routing domains or merge previously independent networks. However, no general technique exists for changing a live network's route redistribution configuration without incurring packet losses and service disruptions. In this paper, we study the problem of how to safely transition between route redistribution configurations. We investigate what anomalies may occur in the reconfiguration process, showing that many long-lasting forwarding loops can and do occur if naive techniques are applied. We devise new sufficient conditions for anomaly-free reconfigurations, and we leverage them to build provably safe and practical reconfiguration procedures. Our procedures enable seamless network re-organizations to accomplish both short-term objectives, such as local repair or traffic engineering, and long-term requirement changes.
Stefano Vissicchio, Laurent Vanbever, Luca Cittadini, Geoffrey G. Xie, Olivier Bonaventure
INFOCOM2
2014 SDX: a software defined internet exchange
abstract
BGP severely constrains how networks can deliver traffic over the Internet. Today's networks can only forward traffic based on the destination IP prefix, by selecting among routes offered by their immediate neighbors. We believe Software Defined Networking (SDN) could revolutionize wide-area traffic delivery, by offering direct control over packet-processing rules that match on multiple header fields and perform a variety of actions. Internet exchange points (IXPs) are a compelling place to start, given their central role in interconnecting many networks and their growing importance in bringing popular content closer to end users.
Arpit Gupta, Laurent Vanbever, Muhammad Shahbaz 0001, Sean Patrick Donovan, Brandon Schlinker, Nick Feamster, Jennifer Rexford, Scott Shenker, Russell J. Clark 0001, Ethan Katz-Bassett
SIGCOMM2
2014 SDX: a software defined internet exchange
abstract
BGP severely constrains how networks can deliver traffic over the Internet. Today's networks can only forward traffic based on the destination IP prefix, by selecting among routes offered by their immediate neighbors. We believe Software Defined Networking (SDN) could revolutionize wide-area traffic delivery, by offering direct control over packet-processing rules that match on multiple header fields and perform a variety of actions. Internet exchange points (IXPs) are a compelling place to start, given their central role in interconnecting many networks and their growing importance in bringing popular content closer to end users. To realize a Software Defined IXP (an "SDX"), we need new programming abstractions that allow participating networks to create and run these applications and a runtime that both behaves correctly when interacting with BGP and ensures that applications do not interfere with each other. We must also ensure that the system scales, both in rule-table size and computational overhead. In this demo, we show how we tackle these challenges demonstrating the flexibility and scalability of our SDX platform. The paper also appears in the main program.
Arpit Gupta, Laurent Vanbever, Muhammad Shahbaz 0001, Sean Patrick Donovan, Brandon Schlinker, Nick Feamster, Jennifer Rexford, Scott Shenker, Russell J. Clark 0001, Ethan Katz-Bassett
SIGCOMM2
2013 SoftCell: scalable and flexible cellular core network architecture
abstract
Cellular core networks suffer from inflexible and expensive equipment, as well as from complex control-plane protocols. To address these challenges, we present SoftCell, a scalable architecture that supports fine-grained policies for mobile devices in cellular core networks, using commodity switches and servers. SoftCell enables operators to realize high-level service policies that direct traffic through sequences of middleboxes based on subscriber attributes and applications. To minimize the size of the forwarding tables, SoftCell aggregates traffic along multiple dimensions---the service policy, the base station, and the mobile device---at different switches in the network. Since most traffic originates from mobile devices, SoftCell performs fine-grained packet classification at the access switches, next to the base stations, where software switches can easily handle the state and bandwidth requirements. SoftCell guarantees that packets belonging to the same connection traverse the same sequence of middleboxes in both directions, even in the presence of mobility. We demonstrate that SoftCell improves the scalability and flexibility of cellular core networks by analyzing real LTE workloads, performing micro-benchmarks on our prototype controller as well as large-scale simulations.
Xin Jin 0008, Li Erran Li, Laurent Vanbever, Jennifer Rexford
CoNEXT3
2013 Using routers to build logic circuits: How powerful is BGP?
abstract
Because of its practical relevance, the Border Gateway Protocol (BGP) has been the target of a huge research effort since more than a decade. In particular, many contributions aimed at characterizing the computational complexity of BGP-related problems. In this paper, we answer computational complexity questions by unveiling a fundamental mapping between BGP configurations and logic circuits. Namely, we describe simple networks containing routers with elementary BGP configurations that simulate logic gates, clocks, and flip-flops, and we show how to interconnect them to simulate arbitrary logic circuits. We then investigate the implications of such a mapping on the feasibility of solving BGP fundamental problems, and prove that, under realistic assumptions, BGP has the same computing power as a Turing Machine. We also investigate the impact of restrictions on the expressiveness of BGP policies and route propagation (e.g., route propagation rules in iBGP and Local Transit Policies in eBGP) and the impact of different message timing models. Finally, we show that the mapping is not limited to BGP and can be applied to generic routing protocols that use several metrics.
Marco Chiesa, Luca Cittadini, Giuseppe Di Battista, Laurent Vanbever, Stefano Vissicchio
ICNP4
2013 When the cure is worse than the disease: The impact of graceful IGP operations on BGP
abstract
Network upgrades, performance optimizations and traffic engineering activities often force network operators to adapt their IGP configuration. Recently, several techniques have been proposed to change an IGP configuration (e.g., link weights) in a disruption-free manner. Unfortunately, none of these techniques considers the impact of IGP changes on BGP correctness. In this paper, we show that known reconfiguration techniques can trigger various kinds of BGP anomalies. First, we illustrate the relevance of the problem by performing simulations on a Tier-1 network. Our simulations highlight that even a few link weight changes can produce long-lasting BGP anomalies affecting a significant part of the BGP routing table. Then, we study the problem of finding a reconfiguration ordering which maintains both IGP and BGP correctness. Unfortunately, we show examples in which such an ordering does not exist. Furthermore, we prove that deciding if such an ordering exists is NP-hard. Finally, we provide sufficient conditions and configuration guidelines that enable graceful operations for both IGP and BGP.
Laurent Vanbever, Stefano Vissicchio, Luca Cittadini, Olivier Bonaventure
INFOCOM1
2013 Improving Network Agility With Seamless BGP Reconfigurations
abstract
The network infrastructure of Internet service providers (ISPs) undergoes constant evolution. Whenever new requirements arise (e.g., the deployment of a new Point of Presence or a change in the business relationship with a neighboring ISP), operators need to change the configuration of the network. Due to the complexity of the Border Gateway Protocol (BGP) and the lack of methodologies and tools, maintaining service availability during reconfigurations that involve BGP is a challenge for operators. In this paper, we show that the current best practices to reconfigure BGP do not provide guarantees with respect to traffic disruptions. Then, we study the problem of finding an operational ordering of BGP reconfiguration steps that guarantees no packet loss. Unfortunately, finding such an operational ordering, when it exists, is computationally hard. To enable lossless reconfigurations, we propose a framework that extends current features of carrier-grade routers to run two BGP control planes in parallel. We present a prototype implementation and show the effectiveness of our framework through a case study.
Stefano Vissicchio, Laurent Vanbever, Cristel Pelsser, Luca Cittadini, Pierre François, Olivier Bonaventure
IEEE/ACM Trans. Netw.2
2012 iBGP deceptions: More sessions, fewer routes
abstract
Internal BGP (iBGP) is used to distribute interdomain routes within a single ISP. The interaction between iBGP and the underlying IGP can lead to routing and forwarding anomalies. For this reason, several research contributions aimed at defining sufficient conditions to guarantee anomaly-free configurations and providing design guidelines for network operators. In this paper, we show several anomalies caused by defective dissemination of routes in iBGP. We define the dissemination correctness property, which models the ability of routers to learn at least one route to each destination. By distinguishing between dissemination correctness and existing correctness properties, we show counterexamples that invalidate some results in the literature. Further, we prove that deciding whether an iBGP configuration is dissemination correct is computationally intractable. Even worse, determining whether the addition of a single iBGP session can adversely affect dissemination correctness of an iBGP configuration is also computationally intractable. Finally, we provide sufficient conditions that ensure dissemination correctness, and we leverage them to both formulate design guidelines and revisit prior results.
Stefano Vissicchio, Luca Cittadini, Laurent Vanbever, Olivier Bonaventure
INFOCOM3
2012 Lossless migrations of link-state IGPs
abstract
Network-wide migrations of a running network, such as the replacement of a routing protocol or the modification of its configuration, can improve the performance, scalability, manageability, and security of the entire network. However, such migrations are an important source of concerns for network operators as the reconfiguration campaign can lead to long, service-disrupting outages. In this paper, we propose a methodology that addresses the problem of seamlessly modifying the configuration of link-state Interior Gateway Protocols (IGPs). We illustrate the benefits of our methodology by considering several migration scenarios, including the addition and the removal of routing hierarchy in a running IGP, and the replacement of one IGP with another. We prove that a strict operational ordering can guarantee that the migration will not create any service outage. Although finding a safe ordering is NP-complete, we describe techniques that efficiently find such an ordering and evaluate them using several real-world and inferred ISP topologies. Finally, we describe the implementation of a provisioning system that automatically performs the migration by pushing the configurations on the routers in the appropriate order while monitoring the entire migration process.
Laurent Vanbever, Stefano Vissicchio, Cristel Pelsser, Pierre François, Olivier Bonaventure
IEEE/ACM Trans. Netw.1
2011 Seamless network-wide IGP migrations
abstract
Network-wide migrations of a running network, such as the replacement of a routing protocol or the modification of its configuration, can improve the performance, scalability, manageability, and security of the entire network. However, such migrations are an important source of concerns for network operators as the reconfiguration campaign can lead to long and service-affecting outages.
Laurent Vanbever, Stefano Vissicchio, Cristel Pelsser, Pierre François, Olivier Bonaventure
SIGCOMM1