SDN Security Metric Routing for Vulnerability Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Software Defined Networks (SDNs) lack comprehensive security measures for routing data traffic, making them vulnerable to security threats such as Denial of Service attacks and data leakage due to the lack of consideration for security characteristics of network devices during packet routing.
Innovation Solution
A method and apparatus for calculating and utilizing security metric values for each network device in SDNs, based on configuration, virtual or containerized Network Functions, and cloud infrastructure, to determine secure routing paths, thereby protecting high-priority data from potential security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If SDN separates control plane from data plane to enable centralized control, then network management and resource allocation improve, but security vulnerabilities increase due to centralized controller exposure and lack of security-aware routing
Solution Approach 1:
The system performs preliminary security assessments of network devices before routing packets. Security metric values are calculated in advance based on configuration data, vulnerability information, and threat intelligence, allowing the controller to proactively identify secure paths rather than reacting to threats after they occur.
Solution Approach 2:
The patent introduces security metric values as an intermediary parameter that mediates between the centralized controller and routing decisions. These metrics aggregate multiple security factors into a single quantifiable value that the controller can use to make informed routing decisions without directly processing complex security data.
2Speed
If traditional routing methods are used without security metrics, then packet forwarding speed is maintained, but data security is compromised due to inability to identify secure paths
Solution Approach 1:
The system changes the routing parameter from traditional metrics (bandwidth, latency) to include security metric values. By incorporating security as a routing parameter alongside performance metrics, the system can simultaneously optimize for both speed and security without requiring separate routing tables or complex real-time analysis.
3Reliability
If comprehensive security assessments of all network devices are performed, then routing security improves, but controller computational load and processing time increase
Solution Approach 1:
The patent merges security assessment with existing network device discovery and inventory processes. Instead of performing separate security assessments, the controller consolidates security data collection with routine network management tasks, reducing redundant operations and minimizing additional time requirements.
Solution Approach 2:
Security metric values are calculated and cached in advance for network devices. When routing decisions are required, the controller uses pre-computed security metrics rather than performing real-time security assessments, significantly reducing processing time for actual routing operations.
Data Source
AI summary
Aspects of embodiments provide methods and network controllers for routing packets of data traffic in software defined networks (SDN). A method comprises obtaining, by a network controller for each of a plurality of network devices of the SDN, a security metric value; and determining, by the network controller, a route for the packet in the SDN based on the obtained security metric values for the plurality of network devices. The security metric value of each network device is calculated based on security characteristics of at least one of: a configuration of the network device; a virtual Network Function (vNF) or containerised Network Function (cNF) hosting a network device software instance; and a cloud infrastructure configuration supporting the vNF or cNF hosting the network device.


