Smart SDN Pod Behavior Modeling for Dynamic Intrusion Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions struggle to dynamically adapt to the behaviors of nodes in a software-defined network, making it difficult to effectively segment and protect enterprise computer networks from intrusions, especially in cloud environments where physical links are absent.

Innovation Solution

A system that records and clusters pod behaviors to generate a behavior transition model, using AI to detect misbehaviors and trigger network policy changes, creating pod-specific dynamic firewalls to block suspicious communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If micro segmentations with network policies are implemented to protect enterprise networks from intrusions, then network security is improved, but the complexity of network administration increases as administrators must understand the behaviors of each node to adequately define policies

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork administration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service by automatically generating network policies through AI/ML analysis of node behaviors. The system autonomously monitors, analyzes, and creates segmentation policies without requiring administrators to manually understand complex node behaviors, thus maintaining high security while reducing administrative burden

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the parameter of policy generation from manual configuration to automated AI/ML-driven generation. By transforming the approach from human-based policy definition to machine-based automatic policy creation, the system resolves the contradiction between security requirements and administrative complexity

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If static network policies are used to segment the network, then implementation is simpler, but the system cannot dynamically adapt to changing behaviors of nodes in the network

Engineering Contradiction:
Improvepolicy implementation easeVSAvoiddynamic adaptation to node behaviors
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system applies dynamics by implementing continuous monitoring and real-time analysis of node behaviors using AI/ML algorithms. Network policies are dynamically updated based on observed behavior changes, enabling the system to adapt to evolving threats and patterns while maintaining automated simplification of policy management

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where node behaviors are continuously monitored, analyzed by AI/ML models, and used to automatically adjust network policies. This closed-loop feedback mechanism enables dynamic adaptation while keeping the implementation process automated and simple

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive monitoring of all node behaviors is implemented to detect intrusions, then detection accuracy is improved, but the computational resources and time required for analysis increase

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial action by focusing AI/ML analysis on critical behavior patterns and anomalies rather than processing all node activities uniformly. The system identifies and prioritizes significant behavioral deviations that indicate potential intrusions, achieving high detection accuracy while reducing overall analysis time through selective focus on the most informative signals

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4497077B1Smart SDN for intrusion prevention
Publication Date: 2026.04.22 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • EP4497077B1 patent drawingFigure 1
  • EP4497077B1 patent drawingFigure 2
  • EP4497077B1 patent drawingFigure 3

AI summary

A method, computer system, and a computer program product for smart SDN is provided. The present invention may include recording and clustering a pod's behavior to generate a behavior transition model for the pod. The present invention may include watching a behavior of the pod and comparing the behavior to the generated behavior transition model. The present invention may include triggering a network policy change based on determining that the behavior of the pod is a misbehavior.