SDN Controller DHCP Snooping for IP Conflict Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In software defined network environments, manual configuration of IP addresses by users can lead to conflicts and security breaches, as unauthorized or malicious IP address assignments can compromise virtual machines and the entire network, highlighting the need for meticulous management of IP address assignments.

Innovation Solution

A network controller monitors DHCP communications in SDN environments by setting a BLOCK-EXCEPT-DHCP status on ports to filter out non-DHCP traffic and uses SpoofGuard policies to ensure legitimate IP address usage, preventing unauthorized address configurations and detecting potential security breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual IP address configuration is allowed, then user flexibility and ease of operation are improved, but IP address conflicts and security breaches increase

Engineering Contradiction:
Improveuser flexibilityVSAvoidIP address conflict prevention
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a DHCP snooping mechanism as an intermediary between users and IP address assignment. The DHCP snooping database acts as a mediator that records authorized IP assignments and enables the network to automatically prevent conflicts and security breaches while maintaining user flexibility in manual configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If DHCP snooping is implemented, then IP address assignment security is improved, but network monitoring complexity increases

Engineering Contradiction:
ImproveIP address assignment securityVSAvoidnetwork monitoring complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The DHCP snooping mechanism provides self-service by automatically monitoring, recording, and enforcing IP address assignments without requiring complex manual configuration or continuous human intervention. The system autonomously maintains the DHCP snooping database and enforces security policies.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If DHCP traffic is blocked except for authorized traffic, then unauthorized IP usage is prevented, but legitimate traffic may be affected

Engineering Contradiction:
Improveunauthorized IP usageVSAvoidlegitimate traffic flow
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where the DHCP snooping database continuously monitors DHCP transactions and provides feedback to the network controller. This enables dynamic adjustment of port statuses based on authorized assignments, ensuring that legitimate traffic is not blocked while preventing unauthorized usage.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies local quality by setting port-specific statuses (BLOCK-EXCEPT-DHCP or NORMAL) based on the local DHCP assignment context. Each port's filtering behavior is customized according to its specific DHCP snooping status, allowing precise control that distinguishes between legitimate and unauthorized traffic at the local level.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11831677B2DHCP-communications monitoring by a network controller in software defined network environments
Publication Date: 2023.11.28 VMWARE INC
  • US11831677B2 patent drawing
  • US11831677B2 patent drawing
  • US11831677B2 patent drawing

AI summary

Methods and apparatus to manage a dynamic deployment environment including one or more virtual machines is provided herein. A disclosed example includes involves: scanning, by executing a computer readable instruction with a processor, the virtual machines in the deployment environment to identify a service installed on any of the virtual machines; determining, by executing a computer readable instruction with the processor, the identified service corresponds to a service monitoring rule; determining, by executing a computer readable instruction with the processor, that a monitoring agent identified by the service monitoring rule is installed on the one or more virtual machines on which the service is installed; and configuring the monitoring agent, by executing a computer readable instruction with the processor, to monitor the service in accordance with the service monitoring rule on the at least one of the virtual machines on which the service is installed.