Transient Domain-Wide Policy Removal via Synchronized Controller
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network management systems face challenges in efficiently removing obsolete policies from network devices after a DDoS attack, leading to memory consumption and difficult management, as these policies often require manual configuration and reconfiguration, and can be lost due to router reboots or message loss.
Innovation Solution
Implementing transient domain-wide policies that are automatically generated and removed based on changing network conditions, using a controller to monitor traffic and send commands to network devices to remove policies simultaneously, without requiring additional interaction with the application control plane or maintaining external application state.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If policies are manually removed from network devices after a DDoS attack, then router management becomes difficult and memory is consumed by obsolete policies, but automated removal mechanisms increase system complexity and require coordination across multiple devices
Solution Approach 1:
The patent introduces a controller as an intermediary device that manages policy removal across multiple network devices. The controller receives indications of attack cessation, determines which policies should be removed, and sends coordinated removal commands to all relevant network devices. This intermediary approach simplifies individual device operations while centralizing the complexity of coordinated policy management.
Solution Approach 2:
The system implements feedback mechanisms where network devices report policy status and attack conditions to the controller. The controller monitors whether attacks have ceased and uses this feedback to determine when policies should be removed. This feedback loop enables automated decision-making without requiring constant manual intervention.
2Reliability
If policies remain in effect after an attack to ensure security, then security coverage is maintained, but memory consumption increases and troubleshooting becomes difficult
Solution Approach 1:
The patent implements dynamic policy management where policy retention is not static but adapts based on real-time attack conditions. Policies remain active during attacks and are automatically removed when attacks cease, as determined by the controller monitoring network traffic patterns. This dynamic approach ensures security coverage is maintained only when necessary, freeing memory when policies are no longer needed.
Solution Approach 2:
The system changes the operational parameter of policies from permanent to transient based on attack conditions. When an attack is detected, policies are activated; when the attack ceases (determined by monitoring traffic parameters), the policies are removed. This parameter change allows the system to balance security coverage with memory consumption by adjusting policy lifetime based on actual threat conditions.
3Productivity
If automated policy removal is implemented across multiple network devices, then reaction speed to attacks improves and obsolete policies are cleared, but synchronization challenges and message loss can occur
Solution Approach 1:
The controller maintains a record of active policies and their associated attack conditions in advance. When an attack ceases, the controller already has the information needed to determine which policies should be removed, eliminating the need for devices to query or negotiate. This preliminary preparation enables rapid coordinated removal across all devices without synchronization delays.
Solution Approach 2:
The controller sends removal commands to multiple network devices based on copied information about which policies are active where. Each device receives a copy of the relevant policy removal instruction from the controller, ensuring consistent action across the network without requiring inter-device communication or complex synchronization protocols.
4Ease of manufacture
If manual policy configuration is used, then policy implementation is simple at individual devices, but coordination across the network domain becomes difficult and time-consuming
Solution Approach 1:
The controller provides a universal management function that handles policy removal for all network devices in the domain. Instead of requiring separate manual configuration at each device, the single controller performs the multi-functional role of monitoring attacks, determining policy removal needs, and coordinating removal across all devices. This universal approach simplifies individual device operations while eliminating coordination time through centralized management.
Data Source
AI summary
Techniques are provided for, at an administrative device in a network domain, monitoring a network traffic flow parameter to determine whether a presently applied domain wide policy configured to control a network traffic flow should be removed. In response to determining that the domain wide policy should be removed, a command is generated which causes removal of the domain wide policy at each one of the plurality of network devices, and the command is sent to each one of the plurality of network devices to cause the domain wide policy to be removed at substantially the same time at each network device. Alternatively, the domain wide policy can be automatically removed by the expiry of a timer or in accordance with a timestamp so that the policy is revoked across the network domain without a need for an explicit network wide control message instructing removal of the policy.


