tcp/ip networking

Designs, implements, debugs, and analyzes systems that send, route, and receive IP packets using the TCP/IP protocol suite, including TCP and UDP transport behavior, protocol internals, and stack components. Works on network stack implementations, packet processing, connection management, congestion control, and related configuration and diagnostics.

tcpipnetworking

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.5
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$187K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This study investigates the non-deterministic nature of Internet user packet routing paths and the mechanisms by which they are influenced by service providers and IP protocol versions. Leveraging five years of large-scale traceroute measurements spanning six ISP types, twenty autonomous systems, and fourteen countries, the work systematically reveals—across multiple nations, diverse ISP categories, and an extended temporal scale—that user-level paths frequently deviate from geographically shortest routes, often exhibiting significant cross-border detours. The research further demonstrates that transitioning between ISPs or upgrading to IPv6 substantially alters routing policies and end-to-end latency, highlighting the pronounced impact of both administrative and protocol-level factors on path selection in real-world networks.

Internet service providersIP routingIPv4/IPv6

Verification and Attack Synthesis for Network Protocols

Nov 02, 2025
MV
Max von Hippel
🏛️ Northeastern University

Ensuring functional correctness and performance resilience of network protocols under component failures and adversarial attacks remains a significant challenge. Method: This paper proposes a synergistic analysis framework integrating formal verification with attack synthesis. It models protocol behavior using a formal specification language and employs logical predicates, trace analysis, and model checking to achieve closed-loop verification—simultaneously establishing correctness guarantees and automatically generating realistic attack scenarios. Contribution/Results: Diverging from conventional unidirectional verification, our approach innovatively embeds attack-path generation directly into the verification workflow, enabling reproducible and interpretable failure attribution. Experimental evaluation across multiple mainstream network protocols demonstrates substantial improvements in vulnerability detection rates and attack-surface characterization accuracy. The results validate the feasibility and practicality of formal methods for deep, security-critical analysis of complex network protocols.

Applying formal methods to analyze protocols under normal and attack conditionsSynthesizing attacks that prevent protocol requirement achievementVerifying network protocol functionality and performance requirements

A Target-Agnostic Protocol-Independent Interface for the Transport Layer

Sep 25, 2025
PM
Pedro Mizuno
🏛️ University of Waterloo | AMD | NVIDIA

Transport-layer protocol development is hindered by environmental heterogeneity and the absence of high-level, target-agnostic programming abstractions, impeding automated analysis, formal verification, and programmable transport research. To address this, we propose TINF—the first event-driven, state-aware, high-level programming abstraction specifically designed for transport protocols—achieving full decoupling between protocol logic and execution targets. TINF employs a C-like restricted syntax to express protocol behavior and introduces a target-agnostic instruction set supporting core operations including data reassembly, packet generation, scheduling, and timer management. It features dual backends: DPDK and Linux XDP. Experimental evaluation demonstrates that TINF significantly improves development efficiency, ensures cross-platform semantic consistency, and establishes a unified foundation for formal modeling and automated verification of transport protocols.

Developing transport protocols using high-level programs with constrained C-like constructsProposing a target-agnostic programming abstraction for transport protocolsReducing development effort and enabling automated analysis for transport layer

Verifying QUIC implementations using Ivy

Dec 07, 2021
CC
Christophe Crochet

Ambiguities in the IETF QUIC specification (draft-29) hinder precise implementation and complicate compliance verification. Method: This work presents the first comprehensive formal model of draft-29, built within the Ivy framework and integrating state-machine modeling, SMT-based constraint solving, and differential testing to automate compliance validation across seven mainstream QUIC client/server implementations. Contribution/Results: Leveraging formal reverse analysis, we systematically uncover specification ambiguities and propose actionable remediation paths. Our approach identifies multiple critical compliance violations across implementations and pinpoints several interoperability-affecting specification ambiguities—directly informing ongoing IETF standard revisions. The methodology establishes a scalable, end-to-end framework for protocol formal verification, bridging high-level specifications with executable conformance checks while supporting both automated bug detection and specification refinement.

Ensuring QUIC implementations comply with IETF specifications.Extending formal representation from draft-18 to draft-29.Identifying and suggesting corrections for ambiguities in QUIC specification.

Compact Data Structures for Network Telemetry

Nov 05, 2023
SL
Shir Landau Feibish
🏛️ The Open University of Israel | University of Maryland | Princeton University

Conventional network telemetry frameworks struggle to support fine-grained traffic measurement, performance diagnostics, and attack detection under stringent memory and computational constraints of high-speed network devices. Method: This paper proposes a lightweight, real-time online telemetry framework that systematically integrates compact data structures—including Bloom filter variants, Count-Min Sketch, and HyperLogLog—with streaming algorithms, hierarchical sampling, and P4-programmable data-plane co-design to comply with hardware limitations. Contribution/Results: Evaluated at line rate exceeding 100 Gbps, the framework reduces memory footprint by over 60% compared to state-of-the-art approaches while maintaining sub-1% flow frequency estimation error. It achieves an optimal trade-off among accuracy, throughput, and resource overhead, thereby significantly enhancing the feasibility and practicality of telemetry in high-bandwidth environments.

Compact data structures for traffic analysisHigh-speed network device limitationsTrade-offs between accuracy and overhead

Latest Papers

What's happening recently
View more

Existing transport-layer hardware struggles to flexibly support the evolution of new protocols due to rigid protocol logic or reliance on protocol-specific assumptions. This work proposes PITA, a novel architecture that reconfigures core components—such as scheduling, packet generation, and data reassembly—through a unified event–state–instruction abstraction model, enabling a protocol-agnostic and line-rate programmable transport-layer datapath. By eliminating protocol-specific assumptions, PITA efficiently supports semantically diverse protocols, including TCP and RoCE, on a single FPGA (Alveo U250) while fully preserving their end-to-end behavioral differences. Experimental results demonstrate that the system meets timing constraints at 250 MHz with low hardware overhead and excellent performance.

data-path designhardware programmabilityNIC architecture

This study addresses the scalability bottleneck in unicast and multicast routing caused by the dual role of IP addresses as both identifiers and locators. It systematically traces the evolution of Internet routing scalability solutions, first articulating the map-and-encap architecture as a unifying paradigm and identifying the essential conditions for its successful deployment. Through historical protocol analysis, architectural comparisons, and conceptual abstraction—encompassing approaches such as BIER and tunnel encapsulation—the work reveals that BGP’s lack of intra-domain egress router topology abstraction is a fundamental limitation. The paper proposes core principles to guide future scalable routing designs, emphasizing the critical roles of locally driven incentives and effective topology abstraction in protocol evolution.

BGPIP addressingmap-and-encap

This work addresses the inefficiencies and semantic inconsistencies arising from separately implementing driver and monitor programs in traditional hardware module testing. To overcome this, the authors propose a domain-specific language (DSL) tailored to hardware communication protocols, which enables the unified specification of both driver and monitor logic through an imperative syntax, thereby ensuring their semantic consistency for the first time. Building upon this DSL, they develop a prototype tool that leverages waveform parsing and transaction-level trace inference techniques to accurately reconstruct protocol-compliant transaction sequences from raw signal waveforms. Experimental results demonstrate that the approach significantly improves development efficiency, with further validation planned on real-world interconnect protocols such as Wishbone and AXI-Stream.

driverhardware communicationmonitor

This work addresses the lack of runtime network-level verification mechanisms in existing application-layer protocols, which traditionally require intrusive modifications to application code. It proposes, for the first time, shifting session-type-driven protocol monitoring into the programmable data plane by leveraging the P4 language to automatically generate packet-level monitors. This approach enforces protocol specifications directly within the network without any changes to applications. By integrating session type theory with network verification algorithms, the method effectively handles real-world network conditions such as packet loss and reordering. The feasibility and practicality of this network-level enforcement are demonstrated through evaluations in microservice and network function scenarios, showing its capability to efficiently enforce complex protocols at scale.

data planenetwork enforcementprotocol monitoring

Hot Scholars

AK

Arup Kumar Sarker

PhD Student, Computer Science, University of Virginia
Deep LearningHPCDistributed ComputingComputer Vision
SG

Stefano Ghidoni

Full Professor, University of Padova, Italy
Computer visionRoboticsArtificial IntelligencePattern Recognition
GC

Georg Carle

Technische Universität München
NetworkingInternet SecurityInternet ArchitectureInternet Measurements
MY

Min Yang

Bytedance
Vision Language ModelComputer VisionVideo Understanding