SDN Controller Cooperative Defense via Local Switch Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In existing software-defined networks (SDNs), the controller's load increases significantly when performing data flow filtering across all subnets, leading to reduced processing performance due to the need to handle all incoming data flows for defense purposes.

Innovation Solution

A method for cooperative defense where a controller receives alarm information from a security device of an attacked subnet, generates flow table information, and forwards it to switching devices across subnets, allowing them to filter data flows, thereby sharing the defense rules and reducing the controller's processing load.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the controller performs data flow filtering on all data flows entering subnets, then network security is improved, but the controller's processing performance deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidcontroller processing performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the network into multiple subnets, each with its own local security device performing filtering operations. This segmentation distributes the processing load from the central controller to local devices, maintaining network security while improving controller performance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces local security devices as intermediaries between the controller and subnets. These security devices receive alarm information from the controller and perform actual filtering operations locally, acting as mediators that relieve the controller's processing burden while maintaining security functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the controller filters all incoming data flows, then defense coverage is improved, but the controller's load increases

Engineering Contradiction:
Improvedefense coverageVSAvoidcontroller load
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the defense function across multiple subnets with local security devices, so each device handles filtering for its local subnet. This maintains comprehensive defense coverage while distributing the quantity of processing work away from the controller.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each subnet is equipped with its own security device that autonomously performs filtering operations on incoming data flows. This self-service approach allows local defense without requiring the controller to process every data flow, reducing controller load while maintaining defense coverage.

Inventive Principle:
Principle #25Self-service

3Reliability

If the controller processes all data flows for defense, then security policy enforcement is improved, but processing speed deteriorates

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent segments data flow processing across multiple local security devices in different subnets. Each device enforces security policies on local data flows independently, maintaining policy enforcement integrity while increasing overall processing speed through parallel operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Local security devices act as intermediaries that enforce security policies locally without requiring central controller processing for each data flow. This intermediary approach maintains security policy enforcement while dramatically improving processing speed by eliminating the single-point bottleneck.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2991292B1Network collaborative defense method, device and system
Publication Date: 2019.12.11 HUAWEI TECH CO LTD
  • EP2991292B1 patent drawingFigure 1~2
  • EP2991292B1 patent drawingFigure 3~4
  • EP2991292B1 patent drawingFigure 5~6

AI summary

Embodiments of the present invention provide a method, an apparatus, and a system for cooperative defense on a network. Alarm information sent by a security device of a first subnet that is being attacked is received by a controller, where the alarm information is feature information of attack information; the controller generates flow table information according to the alarm information, and forwards the flow table information to a switching device of the first subnet and a switching device of at least one second subnet, which is equivalent to that, after detecting an attack, a security device of a subnet generates alarm information, and shares, by using the controller, the alarm information with a switching device of the subnet and a switching device of another subnet that is not being attacked, to form networkwide cooperative defense, thereby enhancing network security. The controller only shares the alarm information, and does not need to process a data flow that enters the network, thereby improving processing performance of the controller.