SDN Controller Intrusion Response for In-Vehicle Network
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Commercial vehicles with V2X communication and in-vehicle networks are vulnerable to attacks, and existing intrusion detection systems lack effective mitigation methods, particularly due to limited computing power.
Innovation Solution
An intrusion prevention system using software-defined networking (SDN) technology, comprising an SDN-enabled switch and controller that monitors and controls packet flow, communicates with an IDS for detection, and updates the flow table based on detection results to block malicious traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If an intrusion detection system is mounted in a vehicle, then intrusion detection capability is provided, but computing power limitations prevent the use of advanced detection algorithms
Solution Approach 1:
The patent extracts the intrusion detection function from the vehicle's onboard system and relocates it to an external server. The vehicle terminal only handles lightweight tasks such as collecting flow table data from the SDN switch and transmitting it to the server, while the computationally intensive intrusion detection algorithms are executed on the server with sufficient computing power.
Solution Approach 2:
The patent introduces an SDN controller as an intermediary between the vehicle's network infrastructure and the intrusion detection system. The SDN controller manages the flow table and communicates with both the SDN switch in the vehicle and the external intrusion detection server, enabling the vehicle to benefit from advanced detection capabilities without requiring high onboard computing power.
2Reliability
If existing intrusion detection methods are used, then detection is performed, but appropriate response and mitigation to attacks cannot be achieved
Solution Approach 1:
The patent implements a feedback mechanism where the intrusion detection server continuously monitors traffic patterns, detects attacks, and sends control instructions back to the SDN switch in the vehicle. When an intrusion is detected, the system dynamically updates the flow table to block malicious traffic, creating a closed-loop response system that adapts to threats in real-time.
Solution Approach 2:
The system performs preliminary actions by pre-configuring the SDN switch with flow table rules that enable rapid response to detected threats. When an attack is identified, the intrusion detection server immediately sends update instructions to modify the flow table, blocking malicious traffic before it can cause significant damage to the vehicle system.
3Productivity
If SDN technology is introduced for intrusion prevention, then real-time monitoring and response are enabled, but system complexity increases
Solution Approach 1:
The patent segments the intrusion prevention system into distinct functional modules: the SDN switch for traffic control, the SDN controller for flow table management, the vehicle terminal for data collection, and the external intrusion detection server for analysis. This segmentation allows each component to perform its specialized function efficiently while reducing the complexity burden on any single element, particularly the vehicle's onboard system.
Data Source
AI summary
Provided are an intrusion prevention system and a method for detecting and responding to a vehicle intrusion by means of an SDN support switch installed in an in-vehicle network (IVN) and an SDN controller communicating with the SDN-enabled switch, the method in which the SDN controller receives a flow table from the SDN-enabled switch, enables an intrusion detection system (IDS) to perform intrusion detection, and updates the flow table on the basis of the intrusion detection execution result.


