Dynamic Property Enforcement in Programmable Data Planes

Network programmers can currently deploy an arbitrary set of protocols in forwarding devices through data plane programming languages such as P4. However, as any other type of software, P4 programs are subject to bugs and misconfigurations. Network verification tools have been proposed as a means of...

Full description

Saved in:
Bibliographic Details
Published inIFIP Networking Conference pp. 1 - 9
Main Authors Neves, Miguel, Huffaker, Bradley, Levchenko, Kirill, Barcellos, Marinho
Format Conference Proceeding
LanguageEnglish
Published IFIP 20.05.2019
Online AccessGet full text
ISSN1861-2288
DOI10.23919/IFIPNetworking.2019.8816830

Cover

Loading…
More Information
Summary:Network programmers can currently deploy an arbitrary set of protocols in forwarding devices through data plane programming languages such as P4. However, as any other type of software, P4 programs are subject to bugs and misconfigurations. Network verification tools have been proposed as a means of ensuring that the network behaves as expected, but these tools typically require programmers to manually model P4 programs, are limited in terms of the properties they can guarantee and frequently face severe scalability issues. In this paper, we argue for a novel approach to this problem. Rather than statically inspecting a network configuration looking for bugs, we propose to enforce networking properties at runtime. To this end, we developed P4box, a system for deploying runtime monitors in programmable data planes. Our results show that P4box allows programmers to easily express a broad range of properties. Moreover, we demonstrate that runtime monitors represent a small overhead to network devices in terms of latency and resource consumption.
ISSN:1861-2288
DOI:10.23919/IFIPNetworking.2019.8816830