NSDI 26 - ZooRoute: Enhancing Cloud-Scale Network Reliability via Candidate Path Provisioning... @UsenixOrg
NSDI 26 - ZooRoute: Enhancing Cloud-Scale Network Reliability via Candidate Path Provisioning...  @UsenixOrg
Uploaded June 2026 | Updated September 2026, 3 weeks ago
ZooRoute: Enhancing Cloud-Scale Network Reliability via Candidate Path Provisioning and Overlay Proactive Rerouting

Xiaoqing Sun, Alibaba Cloud; Xing Li, Zhejiang University and Alibaba Cloud; Xionglie Wei, Tian Pan, Ju Zhang, Bowen Yang, Yi Wang, Ye Yang, Yu Qi, Le Yu, Chenhao Jia, Zhanlong Zhang, Xinyu Chen, Xiaobo Xue, Jianyuan Lu, Shize Zhang, Enge Song, and Yang Song, Alibaba Cloud; Rong Wen, Fudan University and Alibaba Cloud; Biao Lyu, Alibaba Cloud and Hangzhou Alibaba Cloud Feitian Information Technology and Hangzhou Alibaba Feitian Information Technology; Yang Xu, Fudan University; Shunmin Zhu, Alibaba Cloud and Hangzhou Feitian Cloud

Failures are inevitable in production-scale cloud networks, making reliability a critical concern for both cloud service providers (CSPs) and their tenants. Existing network failure recovery solutions either fail to provide timely failover or require underlay upgrades, forcing tenants to deploy their own high availability systems with additional CapEX & OpEx. However, most tenants lack the expertise or willingness to invest in such systems but are highly sensitive to service disruptions. This motivates CSPs to assume the responsibility of fast and deterministic failure recovery as a cloud service.

In this work, we present ZooRoute, a tenant-transparent, underlay-agnostic network failure recovery service in Alibaba Cloud. ZooRoute leverages the overlay layer and enables failure bypass by modifying outer source ports during VXLAN tunnel encapsulation. A set of source port candidates per destination IP are maintained by proactive probing between tunnel endpoints to guarantee one-shot deterministic traffic reroute onto healthy paths. However, scaling such design at planet-scale cloud infra brings challenges such as probing overhead at hypervisors, memory consumption at Tofino gateways, and service disruptions at stateful middleboxes, which we address with a range of novel techniques. Deployed in Alibaba Cloud for 26 months, ZooRoute has significantly improved network reliability, reducing cumulative outage time by 93.19% and masking 98.21% of failures from tenant awareness.

View the full NSDI '26 program at usenix.org/conference/nsdi26/technical-sessions
NSDI 26 - ZooRoute: Enhancing Cloud-Scale Network Reliability via Candidate Path Provisioning...NSDI 26 - Iris: Expressive Traffic Analysis for the Modern InternetNSDI 26 - CStar Gateway: Augmenting Public Cloud Infrastructure for Heterogeneous Network...NSDI 26 - Heuristic Analysis from Source Code via Symbolic-Guided OptimizationNSDI 26 - Di-PS: System-Algorithm Co-Design for Asynchronous and Heterogeneous Cross-cluster...NSDI 26 - DistVS: Large-scale Vector Search with Compute-Memory DisaggregationPEPR 26 - Turning Privacy Risk Assessment Into 20 Questions for DevelopersNSDI 26 - Secure Vickrey Auctions for Online AdvertisingNSDI 26 - Slowpoke: End-to-end Throughput Optimization Modeling for Microservice ApplicationsUSENIX Security 25 - FABLE: Batched Evaluation on Confidential Lookup Tables in 2PCPEPR 26 - How Canva Built Simple, Auditable, and Maintainable Data RetentionNSDI 26 - Cortex: Achieving Low-Latency, Cost-Efficient Remote Data Access For LLM via
USENIX |

NSDI '26 - ZooRoute: Enhancing Cloud-Scale Network Reliability via Candidate Path Provisioning...

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER