SDN Traffic Inspection via Flow Sampling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In software-defined networks, a significant portion of internal 'east-west' traffic goes uninspected due to the overhead of security inspection, making it impractical to route or copy all traffic to an inspection device, thus missing potential malware communications.

Innovation Solution

The method involves sampling traffic randomly or based on threat likelihood and using SDN to redirect or copy selected traffic flows to an inspection device, leveraging SDN controllers for topological awareness and targeting high-risk flows for inspection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all traffic is routed or copied to an inspection device for security inspection, then detection capability is improved, but network overhead and resource consumption increase significantly

Engineering Contradiction:
Improvedetection capabilityVSAvoidnetwork overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements sampling-based traffic inspection where only a subset of traffic flows is selected for inspection rather than all traffic. The system identifies candidate flows and selects representative samples for analysis by the security appliance, achieving detection capability while reducing network overhead and resource consumption to manageable levels.

Inventive Principle:
Principle #16Partial or excessive action

2Productivity

If traffic sampling is implemented, then resource utilization is improved, but detection probability may be reduced

Engineering Contradiction:
Improveresource utilizationVSAvoiddetection probability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system employs feedback mechanisms where inspection results from sampled traffic flows are used to adjust and refine the selection of subsequent candidate flows for inspection. The SDN controller learns from inspection outcomes and dynamically modifies sampling strategies to maintain high detection probability while optimizing resource utilization across the network.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent dynamically changes sampling parameters such as sample rate, selection criteria, and inspection depth based on network conditions, threat levels, and resource availability. By adjusting these parameters, the system optimizes the balance between resource utilization and detection probability, ensuring effective security monitoring without overwhelming network resources.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10205641B2Inspection of traffic via SDN
Publication Date: 2019.02.12 CISCO TECHNOLOGY INC
  • US10205641B2 patent drawing
  • US10205641B2 patent drawing
  • US10205641B2 patent drawing

AI summary

A method and related apparatus for performing inspection of flows within a software defined network includes identifying a security appliance within a software defined network, identifying candidate traffic flows flowing in the software defined network to be inspected, selecting one of the candidate traffic flows for security inspection, and communicating with a software defined network controller to cause the one of the candidate traffic flows to be redirected towards the security appliance for inspection or to cause the one of the candidate traffic flows to be copied and a resulting copy thereof forwarded to the security appliance for inspection.