SDN Traffic Inspection via Flow Sampling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In software-defined networks, a significant portion of internal 'east-west' traffic goes uninspected due to the overhead of security inspection, making it impractical to route or copy all traffic to an inspection device, thus missing potential malware communications.
Innovation Solution
The method involves sampling traffic randomly or based on threat likelihood and using SDN to redirect or copy selected traffic flows to an inspection device, leveraging SDN controllers for topological awareness and targeting high-risk flows for inspection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all traffic is routed or copied to an inspection device for security inspection, then detection capability is improved, but network overhead and resource consumption increase significantly
Solution Approach 1:
The patent implements sampling-based traffic inspection where only a subset of traffic flows is selected for inspection rather than all traffic. The system identifies candidate flows and selects representative samples for analysis by the security appliance, achieving detection capability while reducing network overhead and resource consumption to manageable levels.
2Productivity
If traffic sampling is implemented, then resource utilization is improved, but detection probability may be reduced
Solution Approach 1:
The system employs feedback mechanisms where inspection results from sampled traffic flows are used to adjust and refine the selection of subsequent candidate flows for inspection. The SDN controller learns from inspection outcomes and dynamically modifies sampling strategies to maintain high detection probability while optimizing resource utilization across the network.
Solution Approach 2:
The patent dynamically changes sampling parameters such as sample rate, selection criteria, and inspection depth based on network conditions, threat levels, and resource availability. By adjusting these parameters, the system optimizes the balance between resource utilization and detection probability, ensuring effective security monitoring without overwhelming network resources.
Data Source
AI summary
A method and related apparatus for performing inspection of flows within a software defined network includes identifying a security appliance within a software defined network, identifying candidate traffic flows flowing in the software defined network to be inspected, selecting one of the candidate traffic flows for security inspection, and communicating with a software defined network controller to cause the one of the candidate traffic flows to be redirected towards the security appliance for inspection or to cause the one of the candidate traffic flows to be copied and a resulting copy thereof forwarded to the security appliance for inspection.


