SDN Controller Threat Remediation via Flow Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security operations centers (SOCs) face delays and inefficiencies in detecting and mitigating security threats due to manual processes and limitations of traditional techniques like intrusion prevention systems and security information and event management (SIEM), which struggle with advanced persistent threats and require improved detection and remediation methods.
Innovation Solution
A system and method that utilizes software-defined networking (SDN) to obtain security information, identify threats, determine SDN flow rule templates from a playbook library, and deploy these rules via an SDN controller to alter network paths, thereby automating the remediation process and reducing the lifetime of security breaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual processes are used to detect and mitigate security threats, then human analysis and decision-making are applied, but detection speed and response time increase significantly
Solution Approach 1:
The system enables automated self-service security remediation where the SDN controller automatically detects threats, selects appropriate flow rules from templates, and executes mitigation actions without requiring manual SOC analyst intervention. This transforms the manual detection-and-response process into an autonomous system that continuously monitors and responds to security incidents in real-time.
Solution Approach 2:
The system pre-configures multiple SDN flow rule templates in a library before security incidents occur. When a threat is detected, the system instantly selects and applies the pre-prepared appropriate template, eliminating the need for real-time manual rule creation and significantly reducing response time while maintaining accurate threat mitigation.
2Difficulty of detecting and measuring
If traditional intrusion prevention systems and SIEM are used, then basic security monitoring is provided, but detection capability for advanced persistent threats remains insufficient
Solution Approach 1:
The system dynamically adapts its detection and response capabilities by selecting from multiple SDN flow rule templates based on the specific threat characteristics. This dynamic template selection allows the system to effectively detect and respond to advanced persistent threats by adjusting its mitigation strategy according to the detected threat type, overcoming the static limitations of traditional intrusion prevention systems.
Solution Approach 2:
The SDN controller acts as an intermediary between threat detection systems and network infrastructure. It receives security information, processes it through template-based logic, and translates it into actionable flow rules that are deployed to network devices. This intermediary layer enhances detection capability for advanced threats while ensuring effective mitigation through coordinated network-wide action.
3Ease of operation
If manual security remediation processes are implemented, then human judgment is applied to security responses, but productivity and efficiency decrease
Solution Approach 1:
The system segments the complex security remediation process into discrete, manageable steps through template-based workflows. Each template represents a specific remediation action that can be independently selected and executed. This segmentation maintains operational flexibility by allowing selective application of appropriate templates while dramatically improving productivity through automated execution of standardized responses.
Solution Approach 2:
The system changes the state of security response from manual analysis to automated parameter-driven execution. By transforming security decisions into parameterized template selections, the system maintains the flexibility of human judgment in template selection while achieving high-speed automated execution, thereby improving both ease of operation and productivity simultaneously.
Data Source
AI summary
Remediating a security threat to a network includes obtaining, from a network, security information about the network to determine traffic patterns of the network, identifying, based on the traffic patterns of the network, a security threat to the network, determining, from a playbook library and a workflow library, a workflow template and at least one software-defined networking (SDN) flow rule template to remediate the security threat, and deploying, via a SDN controller, a SDN flow rule based on the at least one SDN flow rule template in the network to remediate the security threat by altering a control path of the network.


