{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,25]],"date-time":"2025-10-25T14:19:22Z","timestamp":1761401962767,"version":"3.41.0"},"reference-count":57,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2018,10,23]],"date-time":"2018-10-23T00:00:00Z","timestamp":1540252800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2019,2,28]]},"abstract":"<jats:p>Multi-tenancy in the cloud is a double-edged sword. While it enables cost-effective resource sharing, it increases security risks for the hosted applications. Indeed, multiplexing virtual resources belonging to different tenants on the same physical substrate may lead to critical security concerns such as cross-tenants data leakage and denial of service. Particularly, virtual networks isolation failures are among the foremost security concerns in the cloud. To remedy these, automated tools are needed to verify security mechanisms compliance with relevant security policies and standards. However, auditing virtual networks isolation is challenging due to the dynamic and layered nature of the cloud. Particularly, inconsistencies in network isolation mechanisms across cloud-stack layers, namely, the infrastructure management and the implementation layers, may lead to virtual networks isolation breaches that are undetectable at a single layer. In this article, we propose an offline automated framework for auditing consistent isolation between virtual networks in OpenStack-managed cloud spanning over overlay and layer 2 by considering both cloud layers\u2019 views. To capture the semantics of the audited data and its relation to consistent isolation requirement, we devise a multi-layered model for data related to each cloud-stack layer\u2019s view. Furthermore, we integrate our auditing system into OpenStack, and present our experimental results on assessing several properties related to virtual network isolation and consistency. Our results show that our approach can be successfully used to detect virtual network isolation breaches for large OpenStack-based data centers in reasonable time.<\/jats:p>","DOI":"10.1145\/3267339","type":"journal-article","created":{"date-parts":[[2018,10,23]],"date-time":"2018-10-23T12:16:16Z","timestamp":1540296976000},"page":"1-35","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["ISOTOP"],"prefix":"10.1145","volume":"22","author":[{"given":"Taous","family":"Madi","sequence":"first","affiliation":[{"name":"CIISE, Concordia University, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yosr","family":"Jarraya","sequence":"additional","affiliation":[{"name":"Ericsson Security Research, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Amir","family":"Alimohammadifar","sequence":"additional","affiliation":[{"name":"CIISE, Concordia University, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Suryadipta","family":"Majumdar","sequence":"additional","affiliation":[{"name":"CIISE, Concordia University, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yushun","family":"Wang","sequence":"additional","affiliation":[{"name":"CIISE, Concordia University, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Makan","family":"Pourzandi","sequence":"additional","affiliation":[{"name":"Ericsson Security Research, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lingyu","family":"Wang","sequence":"additional","affiliation":[{"name":"CIISE, Concordia University, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[{"name":"CIISE, Concordia University, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,10,23]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"org","author":"ISO.","year":"2013","unstructured":"ISO. org . 2013 . ISO\/IEC 11889-1:2009. ISO. org. 2013. ISO\/IEC 11889-1:2009."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/2785966"},{"key":"e_1_2_1_3_1","unstructured":"Amazon. 2017. Amazon Virtual Private Cloud. Retrieved from https:\/\/aws.amazon.com\/vpc.  Amazon. 2017. Amazon Virtual Private Cloud. Retrieved from https:\/\/aws.amazon.com\/vpc."},{"volume-title":"Mathematical Logic for Computer Science","author":"Ben-Ari Mordechai","key":"e_1_2_1_5_1","unstructured":"Mordechai Ben-Ari . 2012. Mathematical Logic for Computer Science . Springer Science 8 Business Media, London. Mordechai Ben-Ari. 2012. Mathematical Logic for Computer Science. Springer Science 8 Business Media, London."},{"volume-title":"Automated Security Analysis of Infrastructure Clouds. Master\u2019s thesis","author":"Bleikertz S\u00f6ren","key":"e_1_2_1_6_1","unstructured":"S\u00f6ren Bleikertz . 2010. Automated Security Analysis of Infrastructure Clouds. Master\u2019s thesis . Technical University of Denmark and Norwegian University of Science and Technology . S\u00f6ren Bleikertz. 2010. Automated Security Analysis of Infrastructure Clouds. Master\u2019s thesis. Technical University of Denmark and Norwegian University of Science and Technology."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046660.2046672"},{"key":"e_1_2_1_8_1","volume-title":"Technical Report RZ3786. IBM.","author":"Bleikertz S\u00f6ren","year":"2010","unstructured":"S\u00f6ren Bleikertz , Thomas Gross , M. Schunter , and K. Eriksson . 2010 . Automating Security Audits of Heterogeneous Virtual Infrastructures . Technical Report RZ3786. IBM. S\u00f6ren Bleikertz, Thomas Gross, M. Schunter, and K. Eriksson. 2010. Automating Security Audits of Heterogeneous Virtual Infrastructures. Technical Report RZ3786. IBM."},{"key":"e_1_2_1_9_1","series-title":"Lecture Notes in Computer Science","volume-title":"Proceedings of ESORICS","author":"Bleikertz S\u00f6ren","unstructured":"S\u00f6ren Bleikertz , Thomas Gro\u00df , Matthias Schunter , and Konrad Eriksson . 2011. Automated information flow analysis of virtualized infrastructures . In Proceedings of ESORICS , Lecture Notes in Computer Science , Vol. 6879 , Vijay Atluri and Claudia D\u00edaz (Eds.). Springer , Berlin, 392--415. S\u00f6ren Bleikertz, Thomas Gro\u00df, Matthias Schunter, and Konrad Eriksson. 2011. Automated information flow analysis of virtualized infrastructures. In Proceedings of ESORICS, Lecture Notes in Computer Science, Vol. 6879, Vijay Atluri and Claudia D\u00edaz (Eds.). Springer, Berlin, 392--415."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664274"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818034"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2009.10.017"},{"key":"e_1_2_1_13_1","unstructured":"Cloud Security Alliance. 2014. Cloud Control mMatrix CCM v3.0.1. Retrieved from DOI:https:\/\/cloudsecurityalliance.org\/research\/ccm\/.  Cloud Security Alliance. 2014. Cloud Control mMatrix CCM v3.0.1. Retrieved from DOI:https:\/\/cloudsecurityalliance.org\/research\/ccm\/."},{"key":"e_1_2_1_14_1","volume-title":"Cloud Computing Top Threats","author":"Alliance Cloud Security","year":"2016","unstructured":"Cloud Security Alliance . 2016. Cloud Computing Top Threats in 2016 . Cloud Security Alliance. 2016. Cloud Computing Top Threats in 2016."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2015.8"},{"key":"e_1_2_1_16_1","unstructured":"Crandall et al. 2012. Virtual Networking Management White Paper. Technical Report. DMTF. DMTF Draft White Paper.  Crandall et al. 2012. Virtual Networking Management White Paper. Technical Report. DMTF. DMTF Draft White Paper."},{"volume-title":"Survey: One-Third of Cloud Users","year":"2015","key":"e_1_2_1_17_1","unstructured":"datacenterknowledge. 2015 . Survey: One-Third of Cloud Users \u2019 Clouds are Private, Heavily OpenStack. Retrieved from http:\/\/www.datacenterknowledge.com. datacenterknowledge. 2015. Survey: One-Third of Cloud Users\u2019 Clouds are Private, Heavily OpenStack. Retrieved from http:\/\/www.datacenterknowledge.com."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2016.2556979"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23064"},{"key":"e_1_2_1_20_1","article-title":"An agent based business aware incident detection system for cloud environments","volume":"1","author":"Doelitzscher Frank","year":"2012","unstructured":"Frank Doelitzscher , Christoph Reich , Martin Knahl , Alexander Passfall , and Nathan Clarke . 2012 . An agent based business aware incident detection system for cloud environments . Journal of Cloud Computing 1 , 1 (2012), Article 9, 9 pages. Frank Doelitzscher, Christoph Reich, Martin Knahl, Alexander Passfall, and Nathan Clarke. 2012. An agent based business aware incident detection system for cloud environments. Journal of Cloud Computing 1, 1 (2012), Article 9, 9 pages.","journal-title":"Journal of Cloud Computing"},{"key":"e_1_2_1_21_1","unstructured":"Hewlett Packard Enterprise. 2017. HPE Helion Eucalyptus. Retrieved from http:\/\/www8.hp.com\/us\/en\/cloud\/helion-eucalyptus.html.  Hewlett Packard Enterprise. 2017. HPE Helion Eucalyptus. Retrieved from http:\/\/www8.hp.com\/us\/en\/cloud\/helion-eucalyptus.html."},{"key":"e_1_2_1_22_1","unstructured":"Open Networking Foundation. 2013. OpenFlow Switch Specification. Retrieved from http:\/\/www.gesetze-im-internet.de\/englisch_bdsg.  Open Networking Foundation. 2013. OpenFlow Switch Specification. Retrieved from http:\/\/www.gesetze-im-internet.de\/englisch_bdsg."},{"key":"e_1_2_1_23_1","unstructured":"Google. 2017. Google Compute Engine Subnetworks Beta. Retrieved from https:\/\/cloud.google.com.  Google. 2017. Google Compute Engine Subnetworks Beta. Retrieved from https:\/\/cloud.google.com."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2342441.2342458"},{"key":"e_1_2_1_25_1","unstructured":"Institute of Electrical and Electronics Engineers. 2005. IEEE 802.1q- 2005. 802.1q - Virtual Bridged Local Area Networks.  Institute of Electrical and Electronics Engineers. 2005. IEEE 802.1q- 2005. 802.1q - Virtual Bridged Local Area Networks."},{"key":"e_1_2_1_26_1","unstructured":"ISO Std IEC. 2005. ISO 27002:2005.  ISO Std IEC. 2005. ISO 27002:2005."},{"key":"e_1_2_1_27_1","unstructured":"ISO Std IEC. 2012. ISO 27017.  ISO Std IEC. 2012. ISO 27017."},{"key":"e_1_2_1_28_1","first-page":"99","article-title":"Real time network policy checking using header space analysis. In NSDI. USENIX","author":"Kazemian Peyman","year":"2013","unstructured":"Peyman Kazemian , Michael Chan , Hongyi Zeng , George Varghese , Nick McKeown , and Scott Whyte . 2013 . Real time network policy checking using header space analysis. In NSDI. USENIX , Lombard , IL , 99 -- 111 . Peyman Kazemian, Michael Chan, Hongyi Zeng, George Varghese, Nick McKeown, and Scott Whyte. 2013. Real time network policy checking using header space analysis. In NSDI. USENIX, Lombard, IL, 99--111.","journal-title":"Lombard"},{"key":"e_1_2_1_29_1","volume-title":"Proceedings of the 9th USENIX Symposium on Networked Systems Design and Implementation (NSDI'12)","author":"Kazemian Peyman","year":"2012","unstructured":"Peyman Kazemian , George Varghese , and Nick McKeown . 2012 . Header space analysis: Static checking for networks . In Proceedings of the 9th USENIX Symposium on Networked Systems Design and Implementation (NSDI'12) . USENIX, 113--126. DOI:https:\/\/www.usenix.org\/conference\/nsdi12\/technical-sessions\/presentation\/kazemian. Peyman Kazemian, George Varghese, and Nick McKeown. 2012. Header space analysis: Static checking for networks. In Proceedings of the 9th USENIX Symposium on Networked Systems Design and Implementation (NSDI'12). USENIX, 113--126. DOI:https:\/\/www.usenix.org\/conference\/nsdi12\/technical-sessions\/presentation\/kazemian."},{"volume-title":"Proceedings of the 10th USENIX Symposium on Networked Systems Design and Implementation (NSDI\u201913)","author":"Khurshid Ahmed","key":"e_1_2_1_30_1","unstructured":"Ahmed Khurshid , Xuan Zou , Wenxuan Zhou , Matthew Caesar , and P. Brighten Godfrey . 2013. VeriFlow: Verifying network-wide invariants in real time . In Proceedings of the 10th USENIX Symposium on Networked Systems Design and Implementation (NSDI\u201913) . USENIX, 15--27. DOI:https:\/\/www.usenix.org\/conference\/nsdi13\/technical-sessions\/presentation\/khurshid. Ahmed Khurshid, Xuan Zou, Wenxuan Zhou, Matthew Caesar, and P. Brighten Godfrey. 2013. VeriFlow: Verifying network-wide invariants in real time. In Proceedings of the 10th USENIX Symposium on Networked Systems Design and Implementation (NSDI\u201913). USENIX, 15--27. DOI:https:\/\/www.usenix.org\/conference\/nsdi13\/technical-sessions\/presentation\/khurshid."},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2857705.2857721"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/2043164.2018470"},{"key":"e_1_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Suryadipta Majumdar Yosr Jarraya Taous Madi Amir Alimohammadifar Makan Pourzandi Lingyu Wang and Mourad Debbabi. 2016. In Proactive Verification of Security Compliance for Clouds Through Pre-computation: Application to OpenStack. Springer International Publishing Cham 47--66.  Suryadipta Majumdar Yosr Jarraya Taous Madi Amir Alimohammadifar Makan Pourzandi Lingyu Wang and Mourad Debbabi. 2016. In Proactive Verification of Security Compliance for Clouds Through Pre-computation: Application to OpenStack. Springer International Publishing Cham 47--66.","DOI":"10.1007\/978-3-319-45744-4_3"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/CloudCom.2015.80"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10601-012-9121-3"},{"key":"e_1_2_1_36_1","unstructured":"Microsoft. 2016. Microsoft Azure Virtual Network. Retrieved from https:\/\/azure.microsoft.com.  Microsoft. 2016. Microsoft Azure Virtual Network. Retrieved from https:\/\/azure.microsoft.com."},{"key":"e_1_2_1_37_1","unstructured":"Midokura. 2017. Run MidoNet at Scale. Retrieved from http:\/\/www.midokura.com\/midonet\/.  Midokura. 2017. Run MidoNet at Scale. Retrieved from http:\/\/www.midokura.com\/midonet\/."},{"volume-title":"Proceedings of the 2016 IFIP Networking Conference (IFIP Networking) and Workshops. IEEE, 100--108","author":"Moraes H.","key":"e_1_2_1_38_1","unstructured":"H. Moraes , M. A. M. Vieira , \u00cd. Cunha, and D. Guedes . 2016. Efficient virtual network isolation in multi-tenant data centers on commodity ethernet switches . In Proceedings of the 2016 IFIP Networking Conference (IFIP Networking) and Workshops. IEEE, 100--108 . H. Moraes, M. A. M. Vieira, \u00cd. Cunha, and D. Guedes. 2016. Efficient virtual network isolation in multi-tenant data centers on commodity ethernet switches. In Proceedings of the 2016 IFIP Networking Conference (IFIP Networking) and Workshops. IEEE, 100--108."},{"key":"e_1_2_1_39_1","volume-title":"Proceedings of the 3rd USENIX Conference on Hot Topics in Cloud Computing (HotCloud\u201911)","author":"Mundada Yogesh","year":"2011","unstructured":"Yogesh Mundada , Anirudh Ramachandran , and Nick Feamster . 2011 . Silverline: Data and network isolation for cloud services . In Proceedings of the 3rd USENIX Conference on Hot Topics in Cloud Computing (HotCloud\u201911) . USENIX Association, 13--13. DOI:http:\/\/dl.acm.org\/citation.cfm?id&equals;2170444.2170457 Yogesh Mundada, Anirudh Ramachandran, and Nick Feamster. 2011. Silverline: Data and network isolation for cloud services. In Proceedings of the 3rd USENIX Conference on Hot Topics in Cloud Computing (HotCloud\u201911). USENIX Association, 13--13. DOI:http:\/\/dl.acm.org\/citation.cfm?id&equals;2170444.2170457"},{"key":"e_1_2_1_40_1","unstructured":"Naoyuki Tamura. 2010. Syntax of Sugar CSP description. Retrieved from http:\/\/bach.istc.kobe-u.ac.jp\/sugar\/current\/docs\/syntax.html.  Naoyuki Tamura. 2010. Syntax of Sugar CSP description. Retrieved from http:\/\/bach.istc.kobe-u.ac.jp\/sugar\/current\/docs\/syntax.html."},{"key":"e_1_2_1_41_1","unstructured":"NIST SP. 2003. NIST SP 800-53.  NIST SP. 2003. NIST SP 800-53."},{"key":"e_1_2_1_42_1","unstructured":"OpenStack. 2014. Ossa-2014-008: Routers Can Be Cross Plugged by Other Tenants. Retrieved from https:\/\/security.openstack.org\/ossa\/OSSA-2014-008.html.  OpenStack. 2014. Ossa-2014-008: Routers Can Be Cross Plugged by Other Tenants. Retrieved from https:\/\/security.openstack.org\/ossa\/OSSA-2014-008.html."},{"key":"e_1_2_1_43_1","unstructured":"OpenStack. 2014. OSSA-2014-008: Routers Can Be Cross Plugged by Other Tenants. Retrieved from https:\/\/security.openstack.org\/ossa\/OSSA-2014-008.html.  OpenStack. 2014. OSSA-2014-008: Routers Can Be Cross Plugged by Other Tenants. Retrieved from https:\/\/security.openstack.org\/ossa\/OSSA-2014-008.html."},{"key":"e_1_2_1_44_1","unstructured":"OpenStack. 2014. Policy as a Service (\u201cCongress\u201d). Retrieved from http:\/\/wiki.openstack.org\/wiki\/Congress.  OpenStack. 2014. Policy as a Service (\u201cCongress\u201d). Retrieved from http:\/\/wiki.openstack.org\/wiki\/Congress."},{"key":"e_1_2_1_45_1","unstructured":"OpenStack. 2015. OpenStack Open Source Cloud Computing Software. Retrieved from http:\/\/www.openstack.org.  OpenStack. 2015. OpenStack Open Source Cloud Computing Software. Retrieved from http:\/\/www.openstack.org."},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/2484402.2484406"},{"volume-title":"HotNets","author":"Pfaff Ben","key":"e_1_2_1_47_1","unstructured":"Ben Pfaff , Justin Pettit , Teemu Koponen , Keith Amidon , Martin Casado , and Scott Shenker . 2009. Extending networking into the virtualization layer . In HotNets . ACM , NY. Ben Pfaff, Justin Pettit, Teemu Koponen, Keith Amidon, Martin Casado, and Scott Shenker. 2009. Extending networking into the virtualization layer. In HotNets. ACM, NY."},{"key":"e_1_2_1_48_1","first-page":"500","article-title":"NIST Cloud Computing Standards Roadmap. Technical Report. NIST, Gaithersburg, MD, United States. 108 pages","author":"Pritzker Penny","year":"2013","unstructured":"Penny Pritzker and Patrick D. Gallagher . 2013 . NIST Cloud Computing Standards Roadmap. Technical Report. NIST, Gaithersburg, MD, United States. 108 pages . NIST Special Publication 500 - 291 . Penny Pritzker and Patrick D. Gallagher. 2013. NIST Cloud Computing Standards Roadmap. Technical Report. NIST, Gaithersburg, MD, United States. 108 pages. NIST Special Publication 500-291.","journal-title":"NIST Special Publication"},{"volume-title":"Network and System Security","author":"Probst Thibaut","key":"e_1_2_1_49_1","unstructured":"Thibaut Probst , Eric Alata , Mohamed Ka\u00e2niche , and Vincent Nicomette . 2014. An approach for the automated analysis of network access controls in cloud computing infrastructures . In Network and System Security . Springer , Xi\u2019an, China , 1--14. Thibaut Probst, Eric Alata, Mohamed Ka\u00e2niche, and Vincent Nicomette. 2014. An approach for the automated analysis of network access controls in cloud computing infrastructures. In Network and System Security. Springer, Xi\u2019an, China, 1--14."},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2012.14"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653687"},{"key":"e_1_2_1_52_1","doi-asserted-by":"crossref","unstructured":"Cisco Systems Sean Convery. 2002. Hacking Layer 2: Fun with Ethernet switches. BlackHat Briefings.  Cisco Systems Sean Convery. 2002. Hacking Layer 2: Fun with Ethernet switches. BlackHat Briefings.","DOI":"10.1016\/S1353-4858(02)06003-8"},{"key":"e_1_2_1_53_1","volume-title":"Proceedings of the 2nd International CSP Solver Competition, 65--69","author":"Tamura Naoyuki","year":"2008","unstructured":"Naoyuki Tamura and Mutsunori Banbara . 2008 . Sugar: A CSP to SAT translator based on order encoding . In Proceedings of the 2nd International CSP Solver Competition, 65--69 . Naoyuki Tamura and Mutsunori Banbara. 2008. Sugar: A CSP to SAT translator based on order encoding. In Proceedings of the 2nd International CSP Solver Competition, 65--69."},{"key":"e_1_2_1_54_1","unstructured":"VMware. 2017. vCloud Director. Retrieved from https:\/\/www.vmware.com\/fr\/products\/vcloud-director.html.  VMware. 2017. vCloud Director. Retrieved from https:\/\/www.vmware.com\/fr\/products\/vcloud-director.html."},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/2774993.2775067"},{"key":"e_1_2_1_56_1","volume-title":"Lam","author":"Yang Hongkun","year":"2013","unstructured":"Hongkun Yang and Simon S . Lam . 2013 . Real-time verification of network properties using atomic predicates. In Proceedings of ICNP. IEEE , 1--11. Hongkun Yang and Simon S. Lam. 2013. Real-time verification of network properties using atomic predicates. In Proceedings of ICNP. IEEE, 1--11."},{"key":"e_1_2_1_57_1","volume-title":"Proceedings of NSDI\u201914","author":"Zeng Hongyi","year":"2014","unstructured":"Hongyi Zeng , Shidong Zhang , Fei Ye , Vimalkumar Jeyakumar , Mickey Ju , Junda Liu , Nick McKeown , and Amin Vahdat . 2014 . Libra: Divide and conquer to verify forwarding tables in huge networks . In Proceedings of NSDI\u201914 . USENIX Association, Seattle, WA, 87--99. Hongyi Zeng, Shidong Zhang, Fei Ye, Vimalkumar Jeyakumar, Mickey Ju, Junda Liu, Nick McKeown, and Amin Vahdat. 2014. Libra: Divide and conquer to verify forwarding tables in huge networks. In Proceedings of NSDI\u201914. USENIX Association, Seattle, WA, 87--99."},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-44594-3"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3267339","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3267339","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T00:57:43Z","timestamp":1750208263000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3267339"}},"subtitle":["Auditing Virtual Networks Isolation Across Cloud Layers in OpenStack"],"short-title":[],"issued":{"date-parts":[[2018,10,23]]},"references-count":57,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2019,2,28]]}},"alternative-id":["10.1145\/3267339"],"URL":"https:\/\/doi.org\/10.1145\/3267339","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"type":"print","value":"2471-2566"},{"type":"electronic","value":"2471-2574"}],"subject":[],"published":{"date-parts":[[2018,10,23]]},"assertion":[{"value":"2017-03-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2018-08-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2018-10-23","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}