SDN Controller Cooperative Defense via Local Switch Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In existing software-defined networks (SDNs), the controller's load increases significantly when performing data flow filtering across all subnets, leading to reduced processing performance due to the need to handle all incoming data flows for defense purposes.
Innovation Solution
A method for cooperative defense where a controller receives alarm information from a security device of an attacked subnet, generates flow table information, and forwards it to switching devices across subnets, allowing them to filter data flows, thereby sharing the defense rules and reducing the controller's processing load.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the controller performs data flow filtering on all data flows entering subnets, then network security is improved, but the controller's processing performance deteriorates
Solution Approach 1:
The patent divides the network into multiple subnets, each with its own local security device performing filtering operations. This segmentation distributes the processing load from the central controller to local devices, maintaining network security while improving controller performance.
Solution Approach 2:
The patent introduces local security devices as intermediaries between the controller and subnets. These security devices receive alarm information from the controller and perform actual filtering operations locally, acting as mediators that relieve the controller's processing burden while maintaining security functionality.
2Reliability
If the controller filters all incoming data flows, then defense coverage is improved, but the controller's load increases
Solution Approach 1:
The patent segments the defense function across multiple subnets with local security devices, so each device handles filtering for its local subnet. This maintains comprehensive defense coverage while distributing the quantity of processing work away from the controller.
Solution Approach 2:
Each subnet is equipped with its own security device that autonomously performs filtering operations on incoming data flows. This self-service approach allows local defense without requiring the controller to process every data flow, reducing controller load while maintaining defense coverage.
3Reliability
If the controller processes all data flows for defense, then security policy enforcement is improved, but processing speed deteriorates
Solution Approach 1:
The patent segments data flow processing across multiple local security devices in different subnets. Each device enforces security policies on local data flows independently, maintaining policy enforcement integrity while increasing overall processing speed through parallel operation.
Solution Approach 2:
Local security devices act as intermediaries that enforce security policies locally without requiring central controller processing for each data flow. This intermediary approach maintains security policy enforcement while dramatically improving processing speed by eliminating the single-point bottleneck.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
Embodiments of the present invention provide a method, an apparatus, and a system for cooperative defense on a network. Alarm information sent by a security device of a first subnet that is being attacked is received by a controller, where the alarm information is feature information of attack information; the controller generates flow table information according to the alarm information, and forwards the flow table information to a switching device of the first subnet and a switching device of at least one second subnet, which is equivalent to that, after detecting an attack, a security device of a subnet generates alarm information, and shares, by using the controller, the alarm information with a switching device of the subnet and a switching device of another subnet that is not being attacked, to form networkwide cooperative defense, thereby enhancing network security. The controller only shares the alarm information, and does not need to process a data flow that enters the network, thereby improving processing performance of the controller.