SDN Controller Threat Treatment Model

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern data centers face increasing cyber threats such as Denial of Service (DOS) attacks, spoofing, and packet eavesdropping, which existing security measures struggle to address effectively in a timely and efficient manner.

Innovation Solution

A software-defined networking (SDN) controller generates optimal threat treatment processes based on historical threat treatment information using machine-learning techniques, creating a threat treatment model that guides users in resolving similar threats, and continuously refines these processes for improved effectiveness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are used to detect and respond to cyber threats, then basic threat detection capability is maintained, but the response time and effectiveness are insufficient against increasing cyber threats

Engineering Contradiction:
Improvethreat response effectivenessVSAvoidthreat resolution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by collecting and analyzing historical threat treatment information before new threats occur. It builds a knowledge base of effective treatments and uses machine learning to predict optimal responses, so when a threat is detected, the system can immediately apply pre-analyzed treatment strategies rather than starting from scratch.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring threat treatment outcomes and using this information to refine its machine learning models. The controller evaluates whether applied treatments were effective and feeds this information back into the system to improve future threat response decisions, creating a continuously improving security system.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If manual threat analysis and treatment process development is performed, then customized security responses can be created, but the time and effort required to resolve threats increases significantly

Engineering Contradiction:
Improvecustomized security response capabilityVSAvoidthreat resolution efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system enables self-service by automatically generating treatment processes using machine learning algorithms that analyze historical data. Instead of requiring security personnel to manually develop response strategies, the system autonomously creates customized treatment plans based on patterns learned from previous threat resolutions, significantly reducing human effort while maintaining adaptability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual mechanical analysis with automated machine learning processes. The controller uses computational algorithms to analyze threat patterns and generate treatment strategies, substituting human cognitive processes with automated computational systems that can process information faster and scale more efficiently.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If historical threat treatment information is collected and analyzed using machine-learning technologies, then optimal treatment processes can be generated, but the complexity of the security system increases

Engineering Contradiction:
Improvetreatment process optimization accuracyVSAvoidsecurity system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system uses an SDN controller as an intermediary between the complex machine learning models and the actual network security devices. The controller handles the complexity of data collection, analysis, and model training, while presenting simplified treatment commands to network devices, thereby isolating complexity in a manageable component.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The SDN controller serves multiple functions: it acts as a data collection point, a machine learning processing unit, a treatment generation engine, and a communication hub between security devices and network infrastructure. This multi-functionality consolidates complexity into a single universal component rather than requiring separate specialized systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11228603B1Learning driven dynamic threat treatment for a software defined networking environment
Publication Date: 2022.01.18 JUNIPER NETWORKS INC
  • US11228603B1 patent drawing
  • US11228603B1 patent drawing
  • US11228603B1 patent drawing

AI summary

Techniques are disclosed for providing dynamic threat treatment for a software defined networking (SDN) environment. In one example, a software defined networking controller comprises one or more processors, wherein the one or more processors are configured to: determine that a security device of a network has detected a threat; apply the threat to a threat treatment model, wherein the threat treatment model is generated based on threat treatment information that includes one or more steps used to resolve previous instances of the threat or previous instances of similar threats; and generate one or more treatment processes to resolve the threat based on the threat treatment model.