SDN Controller Threat Remediation via Flow Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security operations centers (SOCs) face delays and inefficiencies in detecting and mitigating security threats due to manual processes and limitations of traditional techniques like intrusion prevention systems and security information and event management (SIEM), which struggle with advanced persistent threats and require improved detection and remediation methods.

Innovation Solution

A system and method that utilizes software-defined networking (SDN) to obtain security information, identify threats, determine SDN flow rule templates from a playbook library, and deploy these rules via an SDN controller to alter network paths, thereby automating the remediation process and reducing the lifetime of security breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual processes are used to detect and mitigate security threats, then human analysis and decision-making are applied, but detection speed and response time increase significantly

Engineering Contradiction:
Improvesecurity threat detection accuracyVSAvoidresponse time to security threats
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated self-service security remediation where the SDN controller automatically detects threats, selects appropriate flow rules from templates, and executes mitigation actions without requiring manual SOC analyst intervention. This transforms the manual detection-and-response process into an autonomous system that continuously monitors and responds to security incidents in real-time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures multiple SDN flow rule templates in a library before security incidents occur. When a threat is detected, the system instantly selects and applies the pre-prepared appropriate template, eliminating the need for real-time manual rule creation and significantly reducing response time while maintaining accurate threat mitigation.

Inventive Principle:
Principle #10Preliminary action

2Difficulty of detecting and measuring

If traditional intrusion prevention systems and SIEM are used, then basic security monitoring is provided, but detection capability for advanced persistent threats remains insufficient

Engineering Contradiction:
Improvedetection capability for advanced persistent threatsVSAvoidsecurity threat mitigation effectiveness
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The system dynamically adapts its detection and response capabilities by selecting from multiple SDN flow rule templates based on the specific threat characteristics. This dynamic template selection allows the system to effectively detect and respond to advanced persistent threats by adjusting its mitigation strategy according to the detected threat type, overcoming the static limitations of traditional intrusion prevention systems.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The SDN controller acts as an intermediary between threat detection systems and network infrastructure. It receives security information, processes it through template-based logic, and translates it into actionable flow rules that are deployed to network devices. This intermediary layer enhances detection capability for advanced threats while ensuring effective mitigation through coordinated network-wide action.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If manual security remediation processes are implemented, then human judgment is applied to security responses, but productivity and efficiency decrease

Engineering Contradiction:
Improveflexibility in security response decisionsVSAvoidsecurity remediation efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system segments the complex security remediation process into discrete, manageable steps through template-based workflows. Each template represents a specific remediation action that can be independently selected and executed. This segmentation maintains operational flexibility by allowing selective application of appropriate templates while dramatically improving productivity through automated execution of standardized responses.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the state of security response from manual analysis to automated parameter-driven execution. By transforming security decisions into parameterized template selections, the system maintains the flexibility of human judgment in template selection while achieving high-speed automated execution, thereby improving both ease of operation and productivity simultaneously.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10250627B2Remediating a security threat to a network
Publication Date: 2019.04.02 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10250627B2 patent drawing
  • US10250627B2 patent drawing
  • US10250627B2 patent drawing

AI summary

Remediating a security threat to a network includes obtaining, from a network, security information about the network to determine traffic patterns of the network, identifying, based on the traffic patterns of the network, a security threat to the network, determining, from a playbook library and a workflow library, a workflow template and at least one software-defined networking (SDN) flow rule template to remediate the security threat, and deploying, via a SDN controller, a SDN flow rule based on the at least one SDN flow rule template in the network to remediate the security threat by altering a control path of the network.