发表机构
Microsoft(微软公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对大型数据中心网络RCA的挑战,提出带PAM风格弃权代数的CoreSec系统,结合拓扑感知配置实现稳定可解释的RCA,无需重新调优,可用于超大规模云网络。
AI 中文摘要
大型数据中心网络中的根本原因分析(RCA)极具挑战性,因为遥测数据存在噪声、不完整且异步。基于评分的方法在这些条件下性能下降,常产生不稳定或错误的归因。我们提出\textsc{CoreSec},一种生产级RCA系统,它用PAM风格的弃权代数替代加权融合。遥测代理通过控制标志组合,在证据模糊时产生确定性决策和明确的弃权(不执行)。CoreSec将该代数与感知拓扑的配置结合,捕捉Clos Fabric中的故障面,且随证据积累单调收敛。在超大规模部署后,CoreSec在不同环境中提供稳定且可解释的RCA行为,无需重新调优。我们的经验表明,结合弃权的结构化组合为真实云网络中的自动化RCA构建了实用基础。
英文摘要
Root cause analysis (RCA) in large datacenter networks is challenging because telemetry is noisy, partial, and asynchronous. Score-based approaches degrade under these conditions, often yielding unstable or incorrect attributions. We present \textsc{CoreSec}, a production RCA system that replaces weighted fusion with a PAM-style abstention algebra. Telemetry agents are composed using control flags that yield deterministic decisions and explicit abstention when evidence is ambiguous. CoreSec combines this algebra with topology-aware configurations that capture failure surfaces across Clos fabrics and converge monotonically as evidence accumulates. Deployed at hyperscale, CoreSec provides stable and explainable RCA behavior across diverse environments without retuning. Our experience shows that structured composition with abstention forms a practical foundation for automated RCA in real-world cloud networks.
CommentsPresented at Usenix OSDI 2026. 17 pages, 5 figures, 4 tables
Journal ref20th USENIX Symposium on Operating Systems Design and Implementation (OSDI 26), Seattle, WA, July 2026, pp. 405-421