A Framework for Implementing and Formally Verifying Distributed Systems [pdf]
homes.cs.washington.edu
homes.cs.washington.edu
I like the idea to focus first on the ideal case with no node failure nor network glitch, and to use then system transformers to introduce, in a formally verified way, both the mechanisms and the failures to cope with.
I have now to find time to give it a try !
By the way, a bit of DuckDuckGo gives: