arrow
Return

Network Change Validation with Relational NetKAT

delete2026-01-01
delete0
PRE
AI
H
Han Xu *
Z
Zachary Kincaid
R
Ratul Mahajan
D
David Walker
DOI:10.1145/3776656delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Relational NetKAT (RN) is a new specification language for network change validation. Engineers use RN to specify intended changes by providing a trace relation R, which maps existing packet traces in the pre-change network to intended packet traces in the post-change network. The intended set of traces may then be checked against the actual post-change traces to uncover errors in implementation. Trace relations are constructed compositionally from a language of combinators that include trace insertion, trace deletion, and packet transformation, as well as regular operators for concatenation, union, and iteration of relations. We provide algorithms for converting trace relations into a new form of NetKAT transducer and also for constructing an automaton that recognizes the image of a NetKAT automaton under a NetKAT transducer. These algorithms, together with existing decision procedures for NetKAT automaton equivalence, suffice for validating network changes. We provide a denotational semantics for our specification language, prove our compilation algorithms correct, implement a tool for network change validation, and evaluate it on a set of benchmarks drawn from a production network and Amazon's Batfish toolkit.
Keywords:
Network verification
Change validation
NetKAT
Automata theory

Journal

P
Proceedings of the ACM on Programming Languages-PACMPL
IF:
2.8
Papers:
308
Citations:
4.7K

Organization

U
university of washington
Scholars:
9.1K
Papers: 4.2K
Citations: 2
P
princeton university
Scholars:
3.0K
Papers: 1.6K
Citations: 0