Score
Designs, implements, debugs, and tests software that sends, receives, routes, or processes data across computer networks, including socket-level code, protocol implementations, client–server and peer-to-peer services, and networked middleware. Addresses APIs and libraries for TCP/UDP/HTTP/TLS, asynchronous I/O, concurrency, message passing, and the performance, reliability, and security concerns of distributed communications.
Ensuring functional correctness and performance resilience of network protocols under component failures and adversarial attacks remains a significant challenge. Method: This paper proposes a synergistic analysis framework integrating formal verification with attack synthesis. It models protocol behavior using a formal specification language and employs logical predicates, trace analysis, and model checking to achieve closed-loop verification—simultaneously establishing correctness guarantees and automatically generating realistic attack scenarios. Contribution/Results: Diverging from conventional unidirectional verification, our approach innovatively embeds attack-path generation directly into the verification workflow, enabling reproducible and interpretable failure attribution. Experimental evaluation across multiple mainstream network protocols demonstrates substantial improvements in vulnerability detection rates and attack-surface characterization accuracy. The results validate the feasibility and practicality of formal methods for deep, security-critical analysis of complex network protocols.
This study investigates the non-deterministic nature of Internet user packet routing paths and the mechanisms by which they are influenced by service providers and IP protocol versions. Leveraging five years of large-scale traceroute measurements spanning six ISP types, twenty autonomous systems, and fourteen countries, the work systematically reveals—across multiple nations, diverse ISP categories, and an extended temporal scale—that user-level paths frequently deviate from geographically shortest routes, often exhibiting significant cross-border detours. The research further demonstrates that transitioning between ISPs or upgrading to IPv6 substantially alters routing policies and end-to-end latency, highlighting the pronounced impact of both administrative and protocol-level factors on path selection in real-world networks.
Transport-layer protocol development is hindered by environmental heterogeneity and the absence of high-level, target-agnostic programming abstractions, impeding automated analysis, formal verification, and programmable transport research. To address this, we propose TINF—the first event-driven, state-aware, high-level programming abstraction specifically designed for transport protocols—achieving full decoupling between protocol logic and execution targets. TINF employs a C-like restricted syntax to express protocol behavior and introduces a target-agnostic instruction set supporting core operations including data reassembly, packet generation, scheduling, and timer management. It features dual backends: DPDK and Linux XDP. Experimental evaluation demonstrates that TINF significantly improves development efficiency, ensures cross-platform semantic consistency, and establishes a unified foundation for formal modeling and automated verification of transport protocols.
Conventional network telemetry frameworks struggle to support fine-grained traffic measurement, performance diagnostics, and attack detection under stringent memory and computational constraints of high-speed network devices. Method: This paper proposes a lightweight, real-time online telemetry framework that systematically integrates compact data structures—including Bloom filter variants, Count-Min Sketch, and HyperLogLog—with streaming algorithms, hierarchical sampling, and P4-programmable data-plane co-design to comply with hardware limitations. Contribution/Results: Evaluated at line rate exceeding 100 Gbps, the framework reduces memory footprint by over 60% compared to state-of-the-art approaches while maintaining sub-1% flow frequency estimation error. It achieves an optimal trade-off among accuracy, throughput, and resource overhead, thereby significantly enhancing the feasibility and practicality of telemetry in high-bandwidth environments.
Ambiguities in the IETF QUIC specification (draft-29) hinder precise implementation and complicate compliance verification. Method: This work presents the first comprehensive formal model of draft-29, built within the Ivy framework and integrating state-machine modeling, SMT-based constraint solving, and differential testing to automate compliance validation across seven mainstream QUIC client/server implementations. Contribution/Results: Leveraging formal reverse analysis, we systematically uncover specification ambiguities and propose actionable remediation paths. Our approach identifies multiple critical compliance violations across implementations and pinpoints several interoperability-affecting specification ambiguities—directly informing ongoing IETF standard revisions. The methodology establishes a scalable, end-to-end framework for protocol formal verification, bridging high-level specifications with executable conformance checks while supporting both automated bug detection and specification refinement.
This work addresses the lack of systematic educational resources in high-performance computing (HPC) networking, which poses a significant barrier for researchers entering the field. It presents the first comprehensive integration of the HPC networking stack, covering communication protocol layers, programming interfaces such as MPI, control plane mechanisms, high-speed interconnect technologies, and custom link-layer hardware. The exposition is anchored by a detailed case study of the El Capitan supercomputer architecture at Lawrence Livermore National Laboratory. By offering a well-structured, practice-oriented primer, this contribution fills a critical educational gap and substantially lowers the entry barrier for researchers seeking to master core HPC networking technologies.
This work addresses the inefficiencies and semantic inconsistencies arising from separately implementing driver and monitor programs in traditional hardware module testing. To overcome this, the authors propose a domain-specific language (DSL) tailored to hardware communication protocols, which enables the unified specification of both driver and monitor logic through an imperative syntax, thereby ensuring their semantic consistency for the first time. Building upon this DSL, they develop a prototype tool that leverages waveform parsing and transaction-level trace inference techniques to accurately reconstruct protocol-compliant transaction sequences from raw signal waveforms. Experimental results demonstrate that the approach significantly improves development efficiency, with further validation planned on real-world interconnect protocols such as Wishbone and AXI-Stream.
This study addresses a fundamental misalignment in the Internet’s architecture: while the design remains centered on IP addresses, operational practice has decisively shifted toward DNS names for service identification, reachability, load balancing, and trust management. This divergence between architectural principles and real-world usage exacerbates system complexity, fragility, and security vulnerabilities. The paper systematically uncovers this “name-driven” evolution, framing it as a foundational shift at the architectural level. Through comprehensive analysis of network architecture, empirical investigation of operational practices, and retrospective examination of prominent failure cases, the work elucidates the intricate interactions among DNS, the IP layer, and higher-layer services, revealing the root causes of major outages and operational challenges. These insights lay the theoretical groundwork and provide critical risk awareness for designing future name-oriented network architectures.
Existing transport-layer hardware struggles to flexibly support the evolution of new protocols due to rigid protocol logic or reliance on protocol-specific assumptions. This work proposes PITA, a novel architecture that reconfigures core components—such as scheduling, packet generation, and data reassembly—through a unified event–state–instruction abstraction model, enabling a protocol-agnostic and line-rate programmable transport-layer datapath. By eliminating protocol-specific assumptions, PITA efficiently supports semantically diverse protocols, including TCP and RoCE, on a single FPGA (Alveo U250) while fully preserving their end-to-end behavioral differences. Experimental results demonstrate that the system meets timing constraints at 250 MHz with low hardware overhead and excellent performance.
本文探讨了通过简化TCP/IP协议栈代码以提高数据中心网络性能的可能性。