Dynamic Software Defined Network Isolation for Infected Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network operators face challenges in effectively identifying and mitigating infected devices, particularly those without security patches or malware, which can compromise network security and impact other devices.

Innovation Solution

Dynamic Software Defined Networking (DSDN) provides network-level security by quarantining or isolating infected devices, limiting their network traffic, and creating VPN tunnels for secure communication, thereby preventing malicious activity and protecting both devices and networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network operators use traditional botnet notification and remediation systems to identify and mitigate infected devices, then infected devices can be detected and remediated, but the response time is delayed and the mitigation is not dynamic enough to prevent spread

Engineering Contradiction:
Improvenetwork security protectionVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements dynamic segmentation of network traffic using SDN controllers that can real-time reconfigure network flow rules based on device security status. When a device is identified as infected, the system dynamically creates isolation segments and redirects traffic without manual intervention, enabling rapid response to security threats while maintaining normal network operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system pre-configures security policies and isolation segments before threats occur. SDN controllers maintain ready-to-apply flow rules for common threat scenarios, allowing immediate enforcement of security measures once a device is identified as compromised, eliminating the delay of ad-hoc rule creation during incident response.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If infected devices are completely isolated from the network, then network security is protected, but the devices cannot receive remediation updates or maintain essential communications

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice communication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies differentiated isolation policies to different devices based on their security status and device type. Critical devices receiving security updates can communicate with specific update servers through controlled segments, while fully compromised devices receive complete isolation. This localized quality approach ensures security while maintaining necessary communications for remediation.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The SDN controller acts as an intermediary that manages segmented network paths between isolated devices and authorized communication endpoints. The controller enforces flow rules that allow specific traffic patterns (such as security update downloads) while blocking other communications, enabling controlled interaction without compromising overall network security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If network traffic is monitored and analyzed in real-time to identify infected devices, then security threats can be detected early, but the system complexity and processing requirements increase significantly

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex traffic analysis and security decision-making functions from individual network devices and centralizes them in SDN controllers. The controllers handle sophisticated flow rule management, threat detection logic, and isolation segment configuration, while network switches and routers perform only simple packet forwarding based on controller-provided rules, significantly reducing distributed system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The SDN controller serves as an intermediary between network traffic and security policies, centralizing the complex processing of traffic analysis, threat identification, and response coordination. This centralized mediation simplifies the architecture by eliminating the need for complex security logic in every network device, as the controller handles all sophisticated processing and communicates simple forwarding rules to network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11997126B1Systems and methods for dynamic security micronetwork protection of network connected devices
Publication Date: 2024.05.28 CABLE TELEVISION LAB INC
  • US11997126B1 patent drawing
  • US11997126B1 patent drawing
  • US11997126B1 patent drawing

AI summary

Dynamic Software Defined Networking (DSDN) systems and methods provide secure and isolated subnetworks within a larger network. Each subnetwork may be formed with varied policies and communication restrictions based on at least device type, device grouping, and risk level. The DSDN systems and methods may also be applied to form a network, with or without subnetworks, of devices that are spatially separated, thereby reducing the attack surface of the DSDN-formed network.