SDN Traffic Diversion via Central Controller for DoS Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional solutions for diverting traffic in software defined networks (SDN) are complex, prone to infinite packet loops, and inefficient, lacking optimized paths and resource utilization, especially when providing security services.
Innovation Solution
A method and system that utilize a central controller to operate in 'peace' and 'attack' modes, monitoring traffic and diverting suspicious traffic to security servers via designated diversion fields in packet headers, allowing on-the-fly diversion without prior network provisioning, using the OpenFlow protocol for programming network elements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional solutions are used for diverting traffic in SDN, then traffic diversion can be achieved, but the system becomes complex and prone to infinite packet loops
Solution Approach 1:
The patent introduces a central controller as an intermediary between network elements and security servers. The central controller receives traffic diversion requests from network elements, determines the appropriate security server, and manages the diversion process. This intermediary approach simplifies the diversion operations at network elements while maintaining reliable traffic diversion to security servers, preventing infinite packet loops through centralized control.
Solution Approach 2:
The patent utilizes OpenFlow protocol parameters and flow table entries to dynamically change traffic routing parameters. By modifying flow table rules in the central controller, the system can redirect traffic to security servers without complex hardware reconfiguration. This parameter-based control enables reliable traffic diversion while keeping the system manageable through software-based parameter adjustments rather than complex physical reconfiguration.
2Reliability
If dedicated BGP announcements are used for traffic diversion, then traffic can be redirected to security servers, but the configuration becomes cumbersome and inefficient
Solution Approach 1:
The patent enables network elements to automatically detect attacks and initiate traffic diversion requests to the central controller without manual BGP configuration. The system performs self-service by automatically determining when security intervention is needed and handling the diversion process through standardized OpenFlow protocols, eliminating cumbersome manual configuration while maintaining reliable security service delivery.
Solution Approach 2:
The central controller serves multiple functions: it acts as a traffic diversion manager, security server selector, and network element coordinator. This universal controller handles diverse security requirements through a single standardized interface, making the system easier to operate compared to dedicated BGP announcement mechanisms while ensuring reliable security services through centralized multi-functional management.
3Productivity
If conventional traffic injection methods are used, then processed traffic can be relayed back to the network, but infinite packet loops occur and computing resources are inefficiently utilized
Solution Approach 1:
The patent implements feedback control through the central controller that monitors traffic flow status and dynamically adjusts diversion decisions. The controller receives feedback from network elements about traffic patterns and attack conditions, and provides feedback to security servers about which traffic has been processed. This feedback mechanism prevents infinite packet loops by tracking traffic state and ensures efficient computing resource utilization by making informed diversion decisions based on real-time network conditions.
Data Source
AI summary
A method and system for mitigating of cyber-attacks in a software defined network (SDN) are presented. The method comprises operating a central controller and the SDN in a peace mode; monitoring traffic addressed to at least one destination server to detect at least an attack performed against the at least one destination server; switching an operation of the central controller to an attack mode, upon detection of an attack against the at least one destination server; and instructing, by the central controller, network elements of the SDN to divert all suspicious incoming traffic addressed to the at least one destination server to a security server, thereby mitigating the detected attack.


