Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

History

3 Commits

Repository files navigation

CrossCheck: Network Counter Repair and Validation

CrossCheck is a Python package for repairing and validating inconsistent network telemetry data using Democratic Trust Propagation (DTP) and demand-invariant checking. This work was published at NSDI 2026.

@inproceedings{krentsel2026crosscheck,
title={CrossCheck: Input Validation for WAN Control Systems},
author={Krentsel, Alexander and Iyer, Rishabh and Keslassy, Isaac and Ratnasamy, Sylvia and Modhipalli, Bharath and Shaikh, Anees and Shakir, Rob},
booktitle={20th USENIX Symposium on Networked Systems Design and Implementation (NSDI 26)},
year={2026},
address={Renton, WA, USA},
publisher={USENIX Association}
}

Overview

Network telemetry data—such as interface counter values and traffic demands—is often inconsistent due to measurement errors, packet loss, or misconfiguration. CrossCheck addresses this challenge through:

  1. Repair: Democratic Trust Propagation (DTP) uses a voting mechanism where each router's flow conservation constraints provide independent opinions about correct values. The algorithm iteratively locks high-confidence values and propagates trust to resolve inconsistencies.

  2. Validation: Validates repaired data against demand invariants and optionally path-based predictions to ensure data consistency and accuracy.

The system achieves high repair accuracy (>95%) even with significant measurement errors (10-20%), making it suitable for network monitoring, troubleshooting, and analysis pipelines.

This implementation accompanies the paper "CrossCheck: Input Validation for WAN Control Systems" presented at NSDI 2026.

Installation

We recommend using uv for Python package management:

git clone <repository-url>cd crosscheck
uv pip install -e .

Or with pip:

pip install -e .

Quick Start

importpandasaspdimportjsonfromcrosscheckimportCrossCheck, CrossCheckConfig# Load topology and datawithopen('topology.json') asf:
topology=json.load(f)
df=pd.read_pickle('telemetry.pkl')
# Initialize CrossCheckcc=CrossCheck(topology, CrossCheckConfig(disable_cache=True))
# Run repair and validationresult=cc.process_df(df)
# Inspect resultsprint(f"Repaired {len(result)} snapshots")
print(f"Avg repair confidence: {result['repair_confidence'].mean():.2f}")
print(f"Avg validation confidence: {result['validation_confidence'].mean():.2f}")

Examples

Two complete working examples are provided in the examples/ directory:

  1. simple_example.py: Basic 3-node synthetic network demonstrating core functionality

    cd examples
    uv run python3 simple_example.py

    Shows 36-49% error reduction on a small linear topology (A-B-C).

  2. abilene_example.py: Real-world Abilene network (12 nodes, 15 links)

    cd examples
    uv run python3 abilene_example.py

    Shows 40%+ error reduction on real network telemetry with 98%+ validation pass rate.

See examples/README.md for detailed documentation.

Data Format

Topology (JSON)

{
"nodes": [
{"id": 0, "name": "NodeA"},
{"id": 1, "name": "NodeB"}
],
"links": [
{"source": 0, "target": 1}
],
"external_nodes": ["NodeA", "NodeB"]
}

Telemetry DataFrame (Pickle)

Each row represents a network snapshot with columns:

  • Metadata: timestamp, telemetry_perturbed_type, input_perturbed_type, true_detect_inconsistent
  • Demands (high_*): Traffic demands between node pairs as float values
  • Counters (low_*): Interface counter values as dicts with:
    • ground_truth: Original correct value (for evaluation)
    • perturbed: Measured value with errors
    • corrected: Repaired value (added by algorithm)
    • confidence: Repair confidence score (added by algorithm)

Example counter format:

{
'ground_truth': 100.0,
'perturbed': 92.5,
'corrected': 98.7,
'confidence': 0.85
}

See examples/sample_data/README.md for detailed format specification.

API Reference

Main Classes

CrossCheck: Main pipeline class combining repair and validation

cc=CrossCheck(topology, config=CrossCheckConfig())
result_df=cc.process_df(df, paths_path=None)

CrossCheckConfig: Configuration for the pipeline

config=CrossCheckConfig(
repair_config=RepairConfig(...),
validator_config=ValidatorConfig(...),
disable_cache=False
)

RepairConfig: Configuration for DTP repair algorithm

repair_config=RepairConfig(
num_trials=30, # Number of repair trialssimilarity_threshold=0.05, # Fuzzy matching toleranceseed=42, # Random seed for reproducibilitydisable_cache=False# Enable/disable result caching
)

ValidatorConfig: Configuration for validation

validator_config=ValidatorConfig(
confidence_cutoff=0.0, # Confidence threshold for validationthreshold=0.03, # Percentage equality tolerancecounter_bias_correction=0.024, # Bias correction factordisable_cache=False# Enable/disable result caching
)

Key Methods

  • CrossCheck.process_df(df, paths_path): Process complete DataFrame through repair and validation
  • CrossCheck.repair_row(row, paths): Repair a single row
  • CrossCheck.validate_row(row, paths): Validate a single row
  • DemocraticTrustPropagationRepair.repair_df(df, paths_path): Repair DataFrame (standalone)
  • Validator.validate_df(df, paths_path): Validate DataFrame (standalone)

Architecture

crosscheck/
├── crosscheck.py # Main CrossCheck pipeline
├── dtp.py # Democratic Trust Propagation repair
├── validate.py # Validation logic
├── common_utils.py # Shared utilities (NetworkTopology, etc.)
└── snapshot_cache.py # Performance caching

Requirements

  • Python >= 3.8
  • pandas >= 1.3.0
  • numpy >= 1.20.0
  • tqdm >= 4.60.0

Citation

If you use CrossCheck in your research, please cite:

@inproceedings{krentsel2026crosscheck,
title={CrossCheck: Input Validation for WAN Control Systems},
author={Krentsel, Alexander and Iyer, Rishabh and Keslassy, Isaac and Ratnasamy, Sylvia and Modhipalli, Bharath and Shaikh, Anees and Shakir, Rob},
booktitle={20th USENIX Symposium on Networked Systems Design and Implementation (NSDI 26)},
year={2026},
address={Renton, WA, USA},
publisher={USENIX Association}
}

License

MIT License. See LICENSE file for details.

Contributing

Contributions are welcome! Please open an issue or pull request on GitHub.

Contact

For questions or issues, please open a GitHub issue or contact the authors:

  • Alexander Krentsel (akrentsel@berkeley.edu)
  • Paper: "CrossCheck: Input Validation for WAN Control Systems" (NSDI 2026)

About

No description, website, or topics provided.

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages