Distributed SDN Controller Anomaly Detection via Control Message Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed Software Defined Networking (SDN) environments, existing solutions face challenges in detecting network anomalies due to limited scalability and functionality, particularly in handling large-scale network data and various attack scenarios, with conventional approaches being insufficient for high availability and flexibility.

Innovation Solution

A method and apparatus for detecting network anomalies in a distributed SDN environment that generates and analyzes network characteristic information using control messages, including statistic, event, and stateful information, to provide scalable and flexible anomaly detection without requiring switch customization, utilizing a fully-distributed architecture and high-level APIs for user interaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single SDN controller is used to control the entire network, then centralized control and management are achieved, but the system suffers from single point of failure and limited scalability

Engineering Contradiction:
Improvenetwork availabilityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the single SDN controller into multiple distributed controller nodes that operate independently. Each controller manages a portion of the network, eliminating the single point of failure while maintaining centralized control functions through distributed architecture. This segmentation allows the system to scale by adding more controller nodes without requiring a complete redesign of the control architecture.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If conventional network anomaly detection methods are used in distributed SDN environments, then existing detection capabilities are maintained, but the system cannot effectively handle large-scale network data or detect various attack scenarios

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoiddetection framework complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent develops a universal anomaly detection framework that can handle multiple attack scenarios and large-scale network data through a unified architecture. The system provides high-level APIs that enable flexible configuration for different detection scenarios without requiring separate specialized systems, thus improving detection accuracy while managing complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The detection framework is designed to be dynamic and adaptable, allowing it to adjust to different network conditions, attack types, and data scales. The system can dynamically configure detection parameters and algorithms based on the specific scenario, enabling effective anomaly detection across diverse conditions without requiring a completely different system for each case.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If switch customization is required to implement anomaly detection, then detection functionality can be integrated, but the system loses distribution properties and OpenFlow compatibility

Engineering Contradiction:
Improvedetection functionalityVSAvoidOpenFlow compatibility
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary detection framework that operates between the OpenFlow switches and the control plane, allowing anomaly detection without modifying the switches themselves. This intermediary layer maintains full OpenFlow compatibility while providing sophisticated detection capabilities through standard OpenFlow protocol interactions, thus preserving distribution properties and switch interoperability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10609055B2Method for detecting network anomaly in distributed software defined networking environment, apparatus therefor, and computer program therefor
Publication Date: 2020.03.31 KOREA ADVANCED INST OF SCI & TECH
  • US10609055B2 patent drawing
  • US10609055B2 patent drawing
  • US10609055B2 patent drawing

AI summary

A method, an apparatus, and a computer program for detecting network anomaly in a distributed software defined networking (SDN) environment. The method includes collecting a control message from a distributed SDN controller and generating network characteristic information using the control message. The network characteristic information includes statistic information or event information included in the control message, new calculation information calculated using the statistic information or the event information, and network stateful information. The method, the apparatus, and the computer program for detecting network anomaly have high utilization, scalability, availability, and distribution properties to a user by supporting a variety of functions for detecting network anomaly in the SDN environment and providing a high-level API to the user.