[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-81668-en":3,"doc-seo-81668-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},81668,16904993612988,"Olivia Brown","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","GapFuzz Cross-Plane Divergence Fuzzing for Distributed SDN Controllers","Distributed SDN controllers replicate flow state asynchronously between a master and backups, creating a gap where contradictory backup commits can be serialized by the master, letting the kernel datapath apply actions no node considers authoritative. GapFuzz is a stateful concurrency fuzzer that injects paired conflicting Northbound requests across two non-master replicas, reconstructs global cross-plane state via replica queries and ovs-appctlofproto/trace, and uses a two-phase timing search with a lifetime probe to classify verdicts into four ONOS-derived categories. Experiments on ONOS 2.7 show divergence in 81.7% of attempts, with 99.4% persisting beyond 30 s.","GapFuzz: Cross-Plane Divergence Fuzzing for Distributed SDN  \nControllers  \nMoustapha Awwalou DIOUF  \nSnT, University of Luxembourg [moustapha.diouf@uni.lu](moustapha.diouf@uni.lu)  \nSamuel Ouya  \nCheikh H. KANE Digital University [samuel.ouya@unchk.edu.sn](samuel.ouya@unchk.edu.sn)  \nJacques KLEIN  \nSnT, University of Luxembourg [jacques.klein@uni.lu](jacques.klein@uni.lu)  \nTegawendé F. Bissyandé SnT, University of Luxembourg [tegawende.bissyande@uni.lu](tegawende.bissyande@uni.lu)  \narXiv :2606 . 1 1035v2 [ cs . SE] 10 Jul 2026  \nAbstract  \nDistributed Software-Defined Networking (SDN) clusters replicate flow state asynchronously between a master node and its backups, leaving a window during which two backup nodes can each commit a contradictory rule, the master can serialize both into the data plane, and the kernel datapath can latch onto an action that no node believes authoritative. Existing SDN fuzzers miss this fault: they confine their oracle to the control plane, target a single controller, or do not steer concurrency to provoke replication races.  \nWe present GapFuzz, a stateful concurrency fuzzer for distributed SDN clusters. GapFuzz injects pairs of contradictory Northbound requests on two non-master nodes with controlled inter-injection delay Δ􀁃, and reconstructs the global cross-plane state by querying every replica and the kernel-datapath action through ovs-appctlofproto/trace. A two-phase timing search detects whether a divergence exists, then doubles and bisects on Δ􀁃 to bound the injection-time window; a lifetime probe labels each verdict transient or persistent and assigns it to one of four cross-plane state classes derived from the ONOS 2 . 7 source.  \nOn a three-node ONOS 2.7 cluster, GapFuzz produces a divergent verdict in 81.7% of attempts (􀀣 = 50, Wilson 95% CI [77 .3, 85.4]%); every divergence sits between the cluster’s authoritative state and the kernel datapath. Phase 2 separates a 5 ms race window for one template from a doubling-cap regime (Δ􀁃max = 10.24 s) for six others, and 99.4% of divergences persist past 30 s. Replacing the kerneldatapath probe with the OpenFlow user-space probe used by prior fuzzers drops detection by 26.6 percentage points overall and by 46.5 points after excluding canonicalization-forced verdicts.  \nCCS Concepts  \n• Networks → Programmable networks; • Security and privacy → Network security; • Software and its engineering → Software testing and debugging; • Computing methodologies → Distributed computing methodologies.  \nKeywords  \nSoftware-defined networking, distributed controllers, fuzz testing, race conditions, cross-plane consistency, ONOS, Open vSwitch, replication, software security  \n1 Introduction  \nSoftware-defined networking (SDN) decouples the control plane from the data plane through a logically centralized controller that programs forwarding devices via a southbound protocol such as  \nOpenFlow [19, 28] . Production deployments now span enterprise data centers, wide-area backbones, and cloud platforms [10, 11], and the controller increasingly hosts a third-party application ecosystem accessed through a Northbound REST API. That ecosystem is a primary attack surface: malicious or compromised applications have been shown to subvert the control plane, manipulate topology, poison shared state, and abuse Northbound calls in ways that traditional firewalls cannot interpose on [7–9, 21, 25, 35, 42] . The community has converged on the position that controller-side application threats sit at the top of the SDN risk hierarchy [18, 42] .  \nAs SDN scales, the control plane is no longer a single process: it is replicated across a cluster of cooperating instances that maintain a shared Network Information Base, with one node holding mastership for each switch and the others serving as backups [3, 4, 26] . Mainstream open-source platforms (ONOS, OpenDaylight) and operator deployments alike adopt this design. The shared state is split by purpose: cluster coordination uses c","cbCaie9TJFX08DO2","https://ap.wps.com/l/cbCaie9TJFX08DO2","pdf",1181705,2,1,12,"English","en",105,"# Abstract\n# Introduction\n## SDN replication and asynchronous state\n## Application attack surface in SDN controllers\n## Limits of existing SDN fuzzers and validators\n## GapFuzz approach overview","[{\"question\":\"What cross-plane fault does GapFuzz target in distributed SDN controller clusters?\",\"answer\":\"GapFuzz targets cases where the controller cluster internally converges on one flow-rule state, while the switch kernel datapath effectively enforces a different action, leaving no control-plane interface signal of the discrepancy.\"},{\"question\":\"How does GapFuzz generate the divergence condition?\",\"answer\":\"GapFuzz injects pairs of contradictory Northbound requests onto two non-master nodes, controlling the inter-injection delay Δ􀁃 to steer concurrency and provoke replication races.\"},{\"question\":\"How are divergence results detected and classified by GapFuzz?\",\"answer\":\"GapFuzz reconstructs global cross-plane state by querying every replica and probing the kernel-datapath action via ovs-appctlofproto/trace, then uses timing search and a lifetime probe to determine whether verdicts are transient or persistent and maps them into four cross-plane state classes.\"}]",1784175307,30,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"gapfuzz-cross-plane-divergence-fuzzing-for-distributed-sdn-controllers","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/gapfuzz-cross-plane-divergence-fuzzing-for-distributed-sdn-controllers/81668/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-26","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What cross-plane fault does GapFuzz target in distributed SDN controller clusters?","Question",{"text":75,"@type":76},"GapFuzz targets cases where the controller cluster internally converges on one flow-rule state, while the switch kernel datapath effectively enforces a different action, leaving no control-plane interface signal of the discrepancy.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does GapFuzz generate the divergence condition?",{"text":80,"@type":76},"GapFuzz injects pairs of contradictory Northbound requests onto two non-master nodes, controlling the inter-injection delay Δ􀁃 to steer concurrency and provoke replication races.",{"name":82,"@type":73,"acceptedAnswer":83},"How are divergence results detected and classified by GapFuzz?",{"text":84,"@type":76},"GapFuzz reconstructs global cross-plane state by querying every replica and probing the kernel-datapath action via ovs-appctlofproto/trace, then uses timing search and a lifetime probe to determine whether verdicts are transient or persistent and maps them into four cross-plane state classes.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":29,"slug":121},"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]