SDN Controller Traffic Overload Mitigation via Flow Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for managing traffic overloads in software defined networks (SDNs) require external security servers and additional resources, leading to inefficiencies and increased risk of further overload, and are not effective for a wide range of overload causes beyond denial of service attacks.
Innovation Solution
The SDN controller identifies and controls specific traffic flows contributing to overloads by analyzing packet information and managing nodes along the flow paths, reducing traffic overload without diverting flows to external servers, thereby minimizing resource usage and avoiding additional overload risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic flows are diverted to external security servers for overload management, then traffic overload mitigation is achieved, but additional network resources and infrastructure are required
Solution Approach 1:
The patent extracts the traffic flow control function from external security servers and relocates it to the SDN controller. The SDN controller identifies malicious traffic flows and controls SDN switches to redirect or drop these flows internally, eliminating the need to divert traffic to external servers and reducing network resource consumption.
Solution Approach 2:
The SDN controller acts as an intermediary between the data plane (SDN switches) and the control plane (security policies). It receives indications of traffic overload, analyzes packet information to identify contributing flows, and sends control instructions to switches to manage these flows, thereby resolving overload without external server involvement.
2Reliability
If traffic flows are diverted to external security servers, then overload management is achieved, but the system complexity increases due to additional infrastructure
Solution Approach 1:
The patent merges the traffic flow analysis, identification, and control functions into a single SDN controller that already manages the SDN infrastructure. This consolidation eliminates the need for separate external security servers and their associated infrastructure, reducing system complexity while maintaining overload management capabilities.
Solution Approach 2:
The SDN controller is designed to perform multiple functions including traffic flow management, security policy enforcement, and overload mitigation. This multi-functional approach eliminates the need for dedicated external security servers, thereby reducing infrastructure complexity while achieving comprehensive overload management.
3Reliability
If conventional overload management methods are used, then DoS attack mitigation is achieved, but the solution is not effective for a wide range of overload causes
Solution Approach 1:
The SDN controller implements a universal traffic flow management mechanism that can handle various types of traffic overload including DoS attacks, resource exhaustion, and other malicious activities. By analyzing packet information and identifying contributing flows based on their characteristics rather than specific attack types, the system achieves broad adaptability to different overload causes.
Solution Approach 2:
The system dynamically changes control parameters such as traffic flow routing, switching decisions, and policy enforcement based on the identified characteristics of overloaded flows. This allows the same infrastructure to adapt to different types of overload by modifying control parameters rather than requiring specialized solutions for each attack type.
Data Source
AI summary
For managing a traffic overload in a software defined network having an SDN controller, when an indication of a traffic overload is received, there are steps of identifying traffic flows which contribute to this, identifying nodes of the network controllable by the SDN controller and located along a path of the identified traffic flows before the location of the traffic overload. The SDN controller is used to control the identified nodes to control the identified traffic flows to reduce the traffic overload. By using the SDN controller to control the reduction compared to diverting suspicious traffic flows to a separate external security server, the extra network resources used for carrying the diverted traffic flows are not needed, the separate security server is not needed, and the risk of such diverted traffic flows themselves causing overloads is reduced. It can be applicable to a range of causes of overload, including denial of service attacks.


