SDN Security Metric Routing for Vulnerability Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Software Defined Networks (SDNs) lack comprehensive security measures for routing data traffic, making them vulnerable to security threats such as Denial of Service attacks and data leakage due to the lack of consideration for security characteristics of network devices during packet routing.

Innovation Solution

A method and apparatus for calculating and utilizing security metric values for each network device in SDNs, based on configuration, virtual or containerized Network Functions, and cloud infrastructure, to determine secure routing paths, thereby protecting high-priority data from potential security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SDN separates control plane from data plane to enable centralized control, then network management and resource allocation improve, but security vulnerabilities increase due to centralized controller exposure and lack of security-aware routing

Engineering Contradiction:
Improvenetwork management capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security assessments of network devices before routing packets. Security metric values are calculated in advance based on configuration data, vulnerability information, and threat intelligence, allowing the controller to proactively identify secure paths rather than reacting to threats after they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces security metric values as an intermediary parameter that mediates between the centralized controller and routing decisions. These metrics aggregate multiple security factors into a single quantifiable value that the controller can use to make informed routing decisions without directly processing complex security data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If traditional routing methods are used without security metrics, then packet forwarding speed is maintained, but data security is compromised due to inability to identify secure paths

Engineering Contradiction:
Improvepacket forwarding speedVSAvoiddata security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system changes the routing parameter from traditional metrics (bandwidth, latency) to include security metric values. By incorporating security as a routing parameter alongside performance metrics, the system can simultaneously optimize for both speed and security without requiring separate routing tables or complex real-time analysis.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive security assessments of all network devices are performed, then routing security improves, but controller computational load and processing time increase

Engineering Contradiction:
Improverouting securityVSAvoidsecurity metric calculation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges security assessment with existing network device discovery and inventory processes. Instead of performing separate security assessments, the controller consolidates security data collection with routine network management tasks, reducing redundant operations and minimizing additional time requirements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Security metric values are calculated and cached in advance for network devices. When routing decisions are required, the controller uses pre-computed security metrics rather than performing real-time security assessments, significantly reducing processing time for actual routing operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240223583A1Methods and Apparatus for Network Control
Publication Date: 2024.07.04 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240223583A1 patent drawing
  • US20240223583A1 patent drawing
  • US20240223583A1 patent drawing

AI summary

Aspects of embodiments provide methods and network controllers for routing packets of data traffic in software defined networks (SDN). A method comprises obtaining, by a network controller for each of a plurality of network devices of the SDN, a security metric value; and determining, by the network controller, a route for the packet in the SDN based on the obtained security metric values for the plurality of network devices. The security metric value of each network device is calculated based on security characteristics of at least one of: a configuration of the network device; a virtual Network Function (vNF) or containerised Network Function (cNF) hosting a network device software instance; and a cloud infrastructure configuration supporting the vNF or cNF hosting the network device.