SDN Traffic Diversion via Central Controller for DoS Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional solutions for diverting traffic in software defined networks (SDN) are complex, prone to infinite packet loops, and inefficient, lacking optimized paths and resource utilization, especially when providing security services.

Innovation Solution

A method and system that utilize a central controller to operate in 'peace' and 'attack' modes, monitoring traffic and diverting suspicious traffic to security servers via designated diversion fields in packet headers, allowing on-the-fly diversion without prior network provisioning, using the OpenFlow protocol for programming network elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional solutions are used for diverting traffic in SDN, then traffic diversion can be achieved, but the system becomes complex and prone to infinite packet loops

Engineering Contradiction:
Improvetraffic diversion reliabilityVSAvoiddiversion operation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a central controller as an intermediary between network elements and security servers. The central controller receives traffic diversion requests from network elements, determines the appropriate security server, and manages the diversion process. This intermediary approach simplifies the diversion operations at network elements while maintaining reliable traffic diversion to security servers, preventing infinite packet loops through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent utilizes OpenFlow protocol parameters and flow table entries to dynamically change traffic routing parameters. By modifying flow table rules in the central controller, the system can redirect traffic to security servers without complex hardware reconfiguration. This parameter-based control enables reliable traffic diversion while keeping the system manageable through software-based parameter adjustments rather than complex physical reconfiguration.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dedicated BGP announcements are used for traffic diversion, then traffic can be redirected to security servers, but the configuration becomes cumbersome and inefficient

Engineering Contradiction:
Improvesecurity service deliveryVSAvoidconfiguration simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables network elements to automatically detect attacks and initiate traffic diversion requests to the central controller without manual BGP configuration. The system performs self-service by automatically determining when security intervention is needed and handling the diversion process through standardized OpenFlow protocols, eliminating cumbersome manual configuration while maintaining reliable security service delivery.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The central controller serves multiple functions: it acts as a traffic diversion manager, security server selector, and network element coordinator. This universal controller handles diverse security requirements through a single standardized interface, making the system easier to operate compared to dedicated BGP announcement mechanisms while ensuring reliable security services through centralized multi-functional management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If conventional traffic injection methods are used, then processed traffic can be relayed back to the network, but infinite packet loops occur and computing resources are inefficiently utilized

Engineering Contradiction:
Improvecomputing resource utilizationVSAvoidpacket loop prevention
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements feedback control through the central controller that monitors traffic flow status and dynamically adjusts diversion decisions. The controller receives feedback from network elements about traffic patterns and attack conditions, and provides feedback to security servers about which traffic has been processed. This feedback mechanism prevents infinite packet loops by tracking traffic state and ensures efficient computing resource utilization by making informed diversion decisions based on real-time network conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10110485B2Techniques for traffic diversion in software defined networks for mitigating denial of service attacks
Publication Date: 2018.10.23 RADWARE LTD
  • US10110485B2 patent drawing
  • US10110485B2 patent drawing
  • US10110485B2 patent drawing

AI summary

A method and system for mitigating of cyber-attacks in a software defined network (SDN) are presented. The method comprises operating a central controller and the SDN in a peace mode; monitoring traffic addressed to at least one destination server to detect at least an attack performed against the at least one destination server; switching an operation of the central controller to an attack mode, upon detection of an attack against the at least one destination server; and instructing, by the central controller, network elements of the SDN to divert all suspicious incoming traffic addressed to the at least one destination server to a security server, thereby mitigating the detected attack.