{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,31]],"date-time":"2026-01-31T10:07:34Z","timestamp":1769854054381,"version":"3.49.0"},"reference-count":18,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2012,9,24]],"date-time":"2012-09-24T00:00:00Z","timestamp":1348444800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGCOMM Comput. Commun. Rev."],"published-print":{"date-parts":[[2012,9,24]]},"abstract":"<jats:p>Networks are complex and prone to bugs. Existing tools that check configuration files and data-plane state operate offline at timescales of seconds to hours, and cannot detect or prevent bugs as they arise.<\/jats:p>\n          <jats:p>\n            Is it possible to\n            <jats:italic>check network-wide invariants in real time<\/jats:italic>\n            , as the network state evolves? The key challenge here is to achieve extremely low latency during the checks so that network performance is not affected. In this paper, we present a preliminary design, VeriFlow, which suggests that this goal is achievable. VeriFlow is a layer between a software-defined networking controller and network devices that checks for network-wide invariant violations dynamically as each forwarding rule is inserted. Based on an implementation using a Mininet OpenFlow network and Route Views trace data, we find that VeriFlow can perform rigorous checking within hundreds of microseconds per rule insertion.\n          <\/jats:p>","DOI":"10.1145\/2377677.2377766","type":"journal-article","created":{"date-parts":[[2012,9,25]],"date-time":"2012-09-25T23:48:08Z","timestamp":1348616888000},"page":"467-472","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":175,"title":["Veriflow"],"prefix":"10.1145","volume":"42","author":[{"given":"Ahmed","family":"Khurshid","sequence":"first","affiliation":[{"name":"University of Illinois at Urbana-Champaign, Urbana, IL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenxuan","family":"Zhou","sequence":"additional","affiliation":[{"name":"University of Illinois at Urbana-Champaign, Urbana, IL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Matthew","family":"Caesar","sequence":"additional","affiliation":[{"name":"University of Illinois at Urbana-Champaign, Urbana, IL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"P. Brighten","family":"Godfrey","sequence":"additional","affiliation":[{"name":"University of Illinois at Urbana-Champaign, Urbana, IL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,9,24]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Mininet: Rapid prototyping for software defined networks. http:\/\/yuba.stanford.edu\/foswiki\/bin\/view\/OpenFlow\/Mininet.  Mininet: Rapid prototyping for software defined networks. http:\/\/yuba.stanford.edu\/foswiki\/bin\/view\/OpenFlow\/Mininet."},{"key":"e_1_2_1_2_1","unstructured":"OpenFlow switch specification. http:\/\/www.openflow.org\/documents\/openflow-spec-v1.1.0.pdf.  OpenFlow switch specification. http:\/\/www.openflow.org\/documents\/openflow-spec-v1.1.0.pdf."},{"key":"e_1_2_1_3_1","unstructured":"Rocketfuel: An ISP topology mapping engine. http:\/\/www.cs.washington.edu\/research\/networking\/rocketfuel\/.  Rocketfuel: An ISP topology mapping engine. http:\/\/www.cs.washington.edu\/research\/networking\/rocketfuel\/."},{"key":"e_1_2_1_4_1","unstructured":"University of Oregon Route Views Project. http:\/\/www.routeviews.org\/.  University of Oregon Route Views Project. http:\/\/www.routeviews.org\/."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866898.1866905"},{"key":"e_1_2_1_6_1","volume-title":"ICNP","author":"Al-Shaer E.","year":"2009","unstructured":"Al-Shaer , E. , Marrero , W. , El-Atawy , A. , and ElBadawi , K. Network configuration in a box: Towards end-to-end verification of network reachability and security . In ICNP ( 2009 ). Al-Shaer, E., Marrero, W., El-Atawy, A., and ElBadawi, K. Network configuration in a box: Towards end-to-end verification of network reachability and security. In ICNP (2009)."},{"key":"e_1_2_1_7_1","volume-title":"NSDI","author":"Canini M.","year":"2012","unstructured":"Canini , M. , Venzano , D. , Peresini , P. , Kostic , D. , and Rexford , J . A NICE way to test OpenFlow applications . In NSDI ( 2012 ). Canini, M., Venzano, D., Peresini, P., Kostic, D., and Rexford, J. A NICE way to test OpenFlow applications. In NSDI (2012)."},{"key":"e_1_2_1_8_1","volume-title":"NSDI","author":"Feamster N.","year":"2005","unstructured":"Feamster , N. , and Balakrishnan , H . Detecting BGP configuration faults with static analysis . In NSDI ( 2005 ). Feamster, N., and Balakrishnan, H. Detecting BGP configuration faults with static analysis. In NSDI (2005)."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2034574.2034812"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1384609.1384625"},{"key":"e_1_2_1_11_1","volume-title":"NSDI","author":"Kazemian P.","year":"2012","unstructured":"Kazemian , P. , Varghese , G. , and McKeown , N. Header space analysis: Static checking for networks . In NSDI ( 2012 ). Kazemian, P., Varghese, G., and McKeown, N. Header space analysis: Static checking for networks. In NSDI (2012)."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2043164.2018470"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1355734.1355746"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2070562.2070569"},{"key":"e_1_2_1_15_1","volume-title":"Can the production network be the testbed? In OSDI","author":"Sherwood R.","year":"2010","unstructured":"Sherwood , R. , Gibb , G. , Yap , K.-K. , Appenzeller , G. , Casado , M. , McKeown , N. , and Parulkar , G . Can the production network be the testbed? In OSDI ( 2010 ). Sherwood, R., Gibb, G., Yap, K.-K., Appenzeller, G., Casado, M., McKeown, N., and Parulkar, G. Can the production network be the testbed? In OSDI (2010)."},{"key":"e_1_2_1_16_1","volume-title":"HotNets","author":"Tavakoli A.","year":"2009","unstructured":"Tavakoli , A. , Casado , M. , Koponen , T. , and Shenker , S . Applying NOX to the datacenter . In HotNets ( 2009 ). Tavakoli, A., Casado, M., Koponen, T., and Shenker, S. Applying NOX to the datacenter. In HotNets (2009)."},{"key":"e_1_2_1_17_1","volume-title":"Network Algorithmics: An interdisciplinary approach to designing fast networked devices","author":"Varghese G.","year":"2004","unstructured":"Varghese , G. Network Algorithmics: An interdisciplinary approach to designing fast networked devices , 2004 . Varghese, G. Network Algorithmics: An interdisciplinary approach to designing fast networked devices, 2004."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.16"}],"container-title":["ACM SIGCOMM Computer Communication Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2377677.2377766","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2377677.2377766","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T12:17:37Z","timestamp":1750249057000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2377677.2377766"}},"subtitle":["verifying network-wide invariants in real time"],"short-title":[],"issued":{"date-parts":[[2012,9,24]]},"references-count":18,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2012,9,24]]}},"alternative-id":["10.1145\/2377677.2377766"],"URL":"https:\/\/doi.org\/10.1145\/2377677.2377766","relation":{},"ISSN":["0146-4833"],"issn-type":[{"value":"0146-4833","type":"print"}],"subject":[],"published":{"date-parts":[[2012,9,24]]},"assertion":[{"value":"2012-09-24","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}