SDN Controller Network Isolation for Attack Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communications networks in vehicles and industrial settings face challenges in rapidly and effectively responding to attacks, such as denial-of-service attacks, without disrupting other system or network domains, and often require software updates to implement countermeasures.
Innovation Solution
A method and device that utilize a software-defined networking controller to dynamically configure filtering, blocking, or forwarding rules within the network, allowing for the isolation of affected data streams or terminal nodes, thereby isolating the impact of an attack without affecting other parts of the network, using infrastructure components like switches and programmable network interfaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software updates are implemented to counter attacks, then the network security is improved, but the response time is delayed and system operations are disrupted
Solution Approach 1:
The system pre-configures multiple forwarding rules including backup paths before attacks occur. When an attack is detected, the pre-configured rules are immediately activated without requiring software updates, enabling instant response while maintaining network security.
Solution Approach 2:
The forwarding device dynamically switches between different forwarding rules based on real-time attack detection. The system can flexibly adjust network traffic routing by activating predefined countermeasure rules, achieving rapid adaptation to threats without system disruption.
2Reliability
If software updates are deployed to implement countermeasures, then the attack response capability is enhanced, but the system stability is compromised during updates
Solution Approach 1:
Countermeasure forwarding rules are pre-configured and stored in the forwarding device before attacks occur. These rules include alternative paths and filtering criteria that can be instantly activated, eliminating the need for disruptive software updates while maintaining system stability.
Solution Approach 2:
The system uses pre-configured forwarding rules as intermediaries to implement security countermeasures. These rules act as a buffer between attack detection and response execution, allowing the system to maintain stable operations while effectively responding to threats.
3Reliability
If the entire network is shut down to stop attack propagation, then the security is improved, but the productivity of unaffected areas is lost
Solution Approach 1:
The system segments the network into isolated zones using selectively applied forwarding rules. When an attack is detected in a specific area, only the affected segment is isolated through targeted rule activation, while other network segments continue operating normally, maintaining overall productivity.
Solution Approach 2:
The forwarding device applies different forwarding rules to different network segments based on localized attack detection. Countermeasures are implemented locally where needed rather than globally, allowing unaffected areas to maintain full operational efficiency while containing security threats.
4Adaptability or versatility
If filtering and blocking rules are dynamically configured, then the adaptability to attacks is improved, but the device complexity increases
Solution Approach 1:
Multiple forwarding rules including various filtering and blocking configurations are pre-configured for different attack scenarios. The forwarding device stores these rules in advance, enabling rapid adaptation to attacks without complex real-time configuration decisions, thus managing device complexity.
5Speed
If pre-configured forwarding rules are used for immediate response, then the response speed is improved, but the adaptability to new attack types is reduced
Solution Approach 1:
The system pre-configures multiple forwarding rules covering various attack scenarios and stores them in the forwarding device. When attacks are detected, the system activates appropriate pre-configured rules for immediate response, while the controller can update the rule set to adapt to new threat types.
Data Source
AI summary
A device and method for operating a communications network in a vehicle, or for operating an industrial communications network; a control entity for the communications network, in particular, a software-defined networking controller, determining a countermeasure after detection of an attack; an infrastructure component being configured as a function of the countermeasure, in particular, by setting at least one filtering, blocking or forwarding rule; and at least one data stream from or to at least one other infrastructure component being isolated by the infrastructure component, in a portion of the communications network; or at least one data stream to or from an end node being isolated by the infrastructure component, in a portion of the communications network.

