Adaptive Virtual Network Security Against Side-Channel Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-defined networking (SDN) in data centers is vulnerable to side-channel attacks, where hackers can exploit timing and other physical implementation-based information from encrypted communication channels, compromising network security even with encryption in place.

Innovation Solution

Implementing dynamically switched security levels for traffic in virtual data centers by monitoring traffic information and user-defined parameters, which involves padding or adding dummy packets to encrypted traffic to obscure side-channel information, thereby enhancing security without degrading system performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If encryption is used to protect network traffic, then data confidentiality is improved, but the system becomes vulnerable to side-channel attacks

Engineering Contradiction:
Improvedata confidentialityVSAvoidside-channel attack vulnerability
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by monitoring traffic patterns and proactively adjusting security measures (such as packet padding or dummy traffic injection) before side-channel attacks can successfully extract information. This anticipatory approach modifies the traffic characteristics in advance to prevent timing analysis attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically changes traffic parameters (packet timing, size, frequency) based on monitored conditions to obscure side-channel information. By varying these parameters adaptively, the system maintains encryption confidentiality while preventing timing-based attacks that exploit consistent traffic patterns.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dynamic security adjustments are made to mitigate side-channel attacks, then security protection is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms by continuously monitoring traffic patterns and using this information to dynamically adjust security measures. The monitoring component detects traffic characteristics, and this feedback drives adaptive responses such as modifying packet timing or injecting dummy traffic, creating a closed-loop security system that responds to actual conditions.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-service by autonomously monitoring its own traffic patterns and automatically adjusting security parameters without external intervention. The virtual switch and monitoring components work together to self-regulate traffic characteristics and apply appropriate security measures based on observed conditions.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If traffic monitoring is implemented to detect side-channel information, then security detection capability is improved, but network performance degradation occurs

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidnetwork performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system introduces an intermediary monitoring component that observes traffic patterns without directly interfering with data transmission. This intermediary layer analyzes traffic characteristics for security detection while allowing normal traffic flow to continue, minimizing performance impact through non-intrusive monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10542039B2Security against side-channel attack in real-time virtualized networks
Publication Date: 2020.01.21 VMWARE INC
  • US10542039B2 patent drawing
  • US10542039B2 patent drawing
  • US10542039B2 patent drawing

AI summary

Aspects of the present disclosure relate to adaptive and user-defined security against side-channel attacks in a virtual network. Traffic in the virtual network can be monitored at the hypervisor level and network security levels, such as padding and inclusion of dummy packets in the traffic stream, may be adaptively switched based on the monitored traffic information. In addition, user-defined security policies can be input to a management console. Thus, the security levels can be adaptive to real-time traffic bandwidth usage in the network and also flexibly specified by the user/administrator, which may be more efficient.