Dynamic Software Defined Network Isolation for Infected Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network operators face challenges in effectively identifying and mitigating infected devices, particularly those without security patches or malware, which can compromise network security and impact other devices.
Innovation Solution
Dynamic Software Defined Networking (DSDN) provides network-level security by quarantining or isolating infected devices, limiting their network traffic, and creating VPN tunnels for secure communication, thereby preventing malicious activity and protecting both devices and networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network operators use traditional botnet notification and remediation systems to identify and mitigate infected devices, then infected devices can be detected and remediated, but the response time is delayed and the mitigation is not dynamic enough to prevent spread
Solution Approach 1:
The patent implements dynamic segmentation of network traffic using SDN controllers that can real-time reconfigure network flow rules based on device security status. When a device is identified as infected, the system dynamically creates isolation segments and redirects traffic without manual intervention, enabling rapid response to security threats while maintaining normal network operations.
Solution Approach 2:
The system pre-configures security policies and isolation segments before threats occur. SDN controllers maintain ready-to-apply flow rules for common threat scenarios, allowing immediate enforcement of security measures once a device is identified as compromised, eliminating the delay of ad-hoc rule creation during incident response.
2Reliability
If infected devices are completely isolated from the network, then network security is protected, but the devices cannot receive remediation updates or maintain essential communications
Solution Approach 1:
The patent applies differentiated isolation policies to different devices based on their security status and device type. Critical devices receiving security updates can communicate with specific update servers through controlled segments, while fully compromised devices receive complete isolation. This localized quality approach ensures security while maintaining necessary communications for remediation.
Solution Approach 2:
The SDN controller acts as an intermediary that manages segmented network paths between isolated devices and authorized communication endpoints. The controller enforces flow rules that allow specific traffic patterns (such as security update downloads) while blocking other communications, enabling controlled interaction without compromising overall network security.
3Reliability
If network traffic is monitored and analyzed in real-time to identify infected devices, then security threats can be detected early, but the system complexity and processing requirements increase significantly
Solution Approach 1:
The patent extracts the complex traffic analysis and security decision-making functions from individual network devices and centralizes them in SDN controllers. The controllers handle sophisticated flow rule management, threat detection logic, and isolation segment configuration, while network switches and routers perform only simple packet forwarding based on controller-provided rules, significantly reducing distributed system complexity.
Solution Approach 2:
The SDN controller serves as an intermediary between network traffic and security policies, centralizing the complex processing of traffic analysis, threat identification, and response coordination. This centralized mediation simplifies the architecture by eliminating the need for complex security logic in every network device, as the controller handles all sophisticated processing and communicates simple forwarding rules to network infrastructure.
Data Source
AI summary
Dynamic Software Defined Networking (DSDN) systems and methods provide secure and isolated subnetworks within a larger network. Each subnetwork may be formed with varied policies and communication restrictions based on at least device type, device grouping, and risk level. The DSDN systems and methods may also be applied to form a network, with or without subnetworks, of devices that are spatially separated, thereby reducing the attack surface of the DSDN-formed network.


