John Sonchack

dblp:145/2967 · DBLP profile ↗
← Back
23ranked-venue papers
10as first author
9since 2021 · last 2026
0000-0002-9127-161XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 12 · 2 first-author · 7 since 2021Security and privacy · 6 · 6 first-authorSoftware engineering, systems software and programming languages · 3 · 2 since 2021Systems, architecture and hardware · 2 · 2 first-author
YearPublicationVenuePosition
2026 VeriLucid: A Verification-aware Data-plane Programming Language
abstract
Correctness is important in data-plane programs, which run on critical infrastructure connecting millions of users. Verification helps programmers build correct software, but current data-plane tools can only check simple properties or require immense programmer effort. As a solution, this paper introduces the first verification-aware data-plane language: VeriLucid. The core idea is to unify programming and specification in one high-level language, with built-in proof automation. Integration makes it natural for programmers to use verification continuously throughout development, like unit testing but with strong guarantees. In evaluation, we show that VeriLucid requires 10X less programmer effort, in terms of lines of code, than other verification tools with comparable expressiveness.
John Sonchack, Pamela Zave, Jennifer Rexford
SIGCOMM1
2025 Automated Optimization of Parameterized Data-Plane Programs With Parasol
abstract
Programmable data planes allow for sophisticated applications that give operators the power to customize the functionality of their networks. Deploying these applications, however, often requires tedious and burdensome optimization of their layout and design, in which programmers must manually write, compile, and test an implementation, adjust the design, and repeat. In this paper we present Parasol, a framework that allows programmers to define general, parameterized network algorithms and automatically optimize their various parameters. The parameters of a Parasol program can represent a wide variety of implementation decisions, and may be optimized for arbitrary, high-level objectives defined by the programmer. Furthermore, optimization may be tailored to particular environments by providing a representative sample of traffic. We show how we implement the Parasol framework, which consists of a sketching language for writing parameterized programs, and a simulation-based optimizer for testing different parameter settings. We evaluate Parasol by implementing a suite of ten data-plane applications, and find that Parasol produces a solution with comparable performance to hand-optimized P4 code within a two-hour time budget.
Mary Hogan, Devon Loehr, John Sonchack, Shir Landau Feibish, Jennifer Rexford, David Walker 0001
IEEE Trans. Netw.3
2024 Beaver: Practical Partial Snapshots for Distributed Cloud Services
Liangcheng Yu, Haoran Zhang 0009, John Sonchack, Dan R. K. Ports, Vincent Liu 0001
OSDI4
2023 SwitchLog: A Logic Programming Language for Network Switches
Vaibhav Mehta, Devon Loehr, John Sonchack, David Walker 0001
PADL3
2022 OrbWeaver: Using IDLE Cycles in Programmable Networks for Opportunistic Coordination
Liangcheng Yu, John Sonchack, Vincent Liu 0001
NSDI2
2022 Cebinae: scalable in-network fairness augmentation
abstract
For public networks like the Internet and those of many clouds, end-host applications can use any congestion control protocol they wish. This protocol diversity and application autonomy are only increasing over time. While in-network support for fairness is an attractive solution for reigning in the inequity, existing solutions still have difficulty scaling to today's networks using today's devices. In this paper, we present Cebinae, a mechanism for augmenting existing networks of legacy hosts with penalties for flows that exceed their max-min fair share. Cebinae is compatible with all of the congestion control protocols in today's Internet, is deployable on commodity programmable switches, and scales orders of magnitude beyond existing alternatives.
Liangcheng Yu, John Sonchack, Vincent Liu 0001
SIGCOMM2
2021 Flightplan: Dataplane Disaggregation and Placement for P4 Programs
Nik Sultana, John Sonchack, Hans Giesen, Isaac Pedisich, Nishanth Shyamkumar, Shivani Burad, André DeHon, Boon Thau Loo
NSDI2
2021 Lucid: a language for control in the data plane
abstract
Programmable switch hardware makes it possible to move fine-grained control logic inside the network data plane, improving performance for a wide range of applications. However, applications with integrated control are inherently hard to write in existing data-plane programming languages such as P4. This paper presents Lucid, a language that raises the level of abstraction for putting control functionality in the data plane. Lucid introduces abstractions that make it easy to write sophisticated data-plane applications with interleaved packet-handling and control logic, specialized type and syntax systems that prevent programmer bugs related to data-plane state, and an open-sourced compiler that translates Lucid programs into P4 optimized for the Intel Tofino. These features make Lucid general and easy to use, as we demonstrate by writing a suite of ten different data-plane applications in Lucid. Working prototypes take well under an hour to write, even for a programmer without prior Tofino experience, have around 10x fewer lines of code compared to P4, and compile efficiently to real hardware. In a stateful firewall written in Lucid, we find that moving control from a switch's CPU to its data-plane processor using Lucid reduces the latency of performance-sensitive operations by over 300X.
John Sonchack, Devon Loehr, Jennifer Rexford, David Walker 0001
SIGCOMM1
2021 Software Packet-Level Network Analytics at Cloud Scale
abstract
As networks grow in speed, scale, and complexity, operating them reliably requires continuous monitoring and increasingly sophisticated analytics. Because of these requirements, the platforms that support analytics in cloud-scale networks face demands for both higher throughput (to keep up with high packet rates) and increased generality and programmability (to cover a wider range of applications). Recent proposals have worked toward these goals by offloading analytics application logic to line-rate programmable data plane hardware, as scaling existing software analytics platforms is prohibitively expensive. The rigid design and constrained resources of data plane devices, however, fundamentally limit the types of analysis and the number of tasks that can run concurrently. In this article, we demonstrate that generality need not be sacrificed for high performance. Rather than offloading entire analytics applications to hardware, the core idea of our work is to offload only critical preprocessing tasks that are shared among applications (e.g., load balancing) to a line-rate hardware frontend while optimizing the core analytics software to exploit properties of network analytics workloads. Based on this design, we present Jetstream, a hybrid platform for network analytics that can run custom software-based analytics pipelines at throughputs of up to 250 million packets per second on a 16-core commodity server. Jetstream makes sophisticated, network-wide packet analytics feasible without compromising on generality or performance.
Oliver Michel, John Sonchack, Greg Cusack, Maziyar Nazari, Eric Keller, Jonathan M. Smith
IEEE Trans. Netw. Serv. Manag.2
2020 DeepMatch: practical deep packet inspection in the data plane using network processors
abstract
Restricting data plane processing to packet headers precludes analysis of payloads to improve routing and security decisions. DeepMatch delivers line-rate regular expression matching on payloads using Network Processors (NPs). It further supports packet reordering to match patterns in flows that cross packet boundaries. Our evaluation shows that an implementation of DeepMatch, on a 40 Gbps Netronome NFP-6000 SmartNIC, achieves up to line rate for streams of unrelated packets and up to 20 Gbps when searches span multiple packets within a flow. In contrast with prior work, this throughput is data-independent and adds no burstiness. DeepMatch opens new opportunities for programmable data planes.
Joel Hypolite, John Sonchack, Shlomo Hershkop, Nathan Dautenhahn, André DeHon, Jonathan M. Smith
CoNEXT2
2020 tpprof: A Network Traffic Pattern Profiler
Nofel Yaseen, John Sonchack, Vincent Liu 0001
NSDI2
2020 Mantis: Reactive Programmable Switches
abstract
For modern data center switches, the ability to---with minimum latency and maximum flexibility--- react to current network conditions is important for managing increasingly dynamic networks. The traditional approach to implementing this type of behavior is through a control plane that is orders of magnitude slower than the speed at which typical data center congestion events occur. More recent alternatives like programmable switches can remember statistics about passing traffic and adjust behavior accordingly, but unfortunately, their capabilities severely limit what can be done.
Liangcheng Yu, John Sonchack, Vincent Liu 0001
SIGCOMM2
2019 TMC: Pay-as-you-Go Distributed Communication
abstract
We revisit the gap between what distributed systems need from the transport layer and what protocols in wide deployment provide. Such a gap complicates the implementation of distributed systems and impacts their performance. We introduce Tunable Multicast Communication (TMC), an abstraction that allows developers to easily specialize communication channels in distributed systems. TMC is presented as a deployable and extensible user-space library that exposes high-level tunable guarantees. TMC has the potential of improving the performance of distributed applications with minimal-to-zero development and deployment effort.
Henri Maxime Demoulin, Nikos Vasilakis, John Sonchack, Isaac Pedisich, Vincent Liu 0001, Boon Thau Loo, Linh T. X. Phan, Jonathan M. Smith, Irene Zhang
APNet3
2019 Ignis: scaling distribution-oblivious systems with light-touch distribution
abstract
Distributed systems offer notable benefits over their centralized counterparts. Reaping these benefits, however, requires burdensome developer effort to identify and rewrite bottlenecked components. Light-touch distribution is a new approach that converts a legacy system into a distributed one using automated transformations. Transformations operate at the boundaries of bottlenecked modules and are parametrizable by light distribution recipes that guide the intended semantics of the resulting distribution. Transformations and recipes operate at runtime, adapting to load by scaling out only saturated components. Our Ignis prototype shows substantial speedups, attractive elasticity characteristics, and memory gains over full replication, achieved by small and backward-compatible code changes.
Nikos Vasilakis, Ben Karel, Yash Palkhiwala, John Sonchack, André DeHon, Jonathan M. Smith
PLDI4
2018 Turboflow: information rich flow record generation on commodity switches
abstract
Fine-grained traffic flow records enable many powerful applications, especially in combination with telemetry systems that supports high coverage, i.e., of every link and at all times. Current solutions, however, make undesirable trade-offs between infrastructure cost and information richness. Switches that generate flow records, e.g., NetFlow switches, are a low cost solution but current designs sacrifice information richness, e.g., by sampling. Information rich alternatives rely heavily on servers, which increases cost to the point that they are impractical for high coverage. In this paper, we present the design, implementation, and evaluation of TurboFlow, a flow record generator for programmable switches that does not compromise on either cost or information richness. TurboFlow produces fine- grained and unsampled flow records with custom features entirely at the switch without relying on any support from external servers. This is a challenge given high traffic rates and the limitations of switch hardware. To overcome, we decompose the flow record generation algorithm and optimize it for the heterogeneous processors in programmable switches. We show that with this design, TurboFlow can support multi-terabit workloads on readily available commodity switches to enable information rich monitoring with high coverage.
John Sonchack, Adam J. Aviv, Eric Keller, Jonathan M. Smith
EuroSys1
2018 Synchronized network snapshots
abstract
When monitoring a network, operators rarely have a finegrained and complete view of the network's state. Instead, today's network monitoring tools generally only measure a single device or path at a time; whole-network metrics are a composition of these independent measurements, i.e., an afterthought. Such tools fail to fully answer a wide range of questions. Is my load balancing algorithm taking advantage of all available paths evenly? How much of my network is concurrently loaded? Is application traffic synchronized? These types of concurrent network behavior are challenging to capture at fine granularity as they involve coordination across the entire network. At the same time, understanding them is essential to the design of network switches, architectures, and protocols.
Nofel Yaseen, John Sonchack, Vincent Liu 0001
SIGCOMM2
2018 Scaling Hardware Accelerated Network Monitoring to Concurrent and Dynamic Queries With *Flow
John Sonchack, Oliver Michel, Adam J. Aviv, Eric Keller, Jonathan M. Smith
USENIX ATC1
2016 Timing-based reconnaissance and defense in software-defined networks
John Sonchack, Anurag Dubey, Adam J. Aviv, Jonathan M. Smith, Eric Keller
ACSAC1
2016 Enabling Practical Software-defined Networking Security Applications with OFX
John Sonchack, Jonathan M. Smith, Adam J. Aviv, Eric Keller
NDSS1
2016 Exploring large scale security system reproducibility with the LESS simulator
abstract
Many network security systems analyze large scale data collected from multiple collaborating domains or aggregated network vantage points. Scale is clearly beneficial for these systems, however it also makes them difficult to design and test. Large scale data sets can be difficult to acquire and may not contain important meta-information (e.g. ground truth). Further, their limited availability can make it extremely difficult to understand how well experimental results would reproduce in different conditions, or at different networks. In this article, we discuss using simulation to overcome these challenges. We present an augmented version of LESS, our recently proposed agent based simulator for evaluating large scale network security systems. LESS uses publicly available data sets and high level parameters to generate synthetic traffic that models large scale, multi-network scenarios. Essentially, LESS allows researchers to “scale up” the data and statistics about networks and attacks that they have access to, so that they can be used to test large scale network security systems. Researchers can also tune LESS’s high level parameters to better understand the sensitivities of their systems, and the reproducibility of their results. The version of LESS that we discuss in this article is extended to allow researchers to study an additional factor of system performance related to reproducibility: deployment location; by modeling the global Internet topology at the Autonomous System level. We demonstrate the applicability and benefits of LESS by tuning it with publicly available traces and then using generated records to reproduce and extend results from several recently proposed large scale security systems. In new experiments, we use LESS to study how deployment location affects large scale security systems. Our results demonstrate that LESS can evoke realistic performance from these systems with minimal tuning and provide insight into the network and topological factors that may affect the reproducibility of their evaluations.
John Sonchack, Adam J. Aviv
J. Comput. Secur.1
2015 POSTER: OFX: Enabling OpenFlow Extensions for Switch-Level Security Applications
abstract
Network Security applications that run on Software Defined Networks (SDNs) often need to analyze and process traffic in advanced ways. Existing approaches to adding such functionality to SDNs suffer from either poor performance, or poor deployability. In this paper, we propose and benchmark OFX: an OpenFlow extension framework that provides a better tradeoff between performance and deployability for SDN security applications by allowing them to dynamically install software modules onto network switches.
John Sonchack, Adam J. Aviv, Eric Keller, Jonathan M. Smith
CCS1
2015 Cross-domain collaboration for improved IDS rule set selection
John Sonchack, Adam J. Aviv, Jonathan M. Smith
J. Inf. Secur. Appl.1
2014 LESS Is More: Host-Agent Based Simulator for Large-Scale Evaluation of Security Systems
John Sonchack, Adam J. Aviv
ESORICS (2)1