I2NSF Security Controller YANG Model for NSF Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack an efficient method for monitoring Network Security Functions (NSFs) within the Interface to Network Security Functions (I2NSF) framework, which is essential for timely detection of malicious activities and anomalous behavior.

Innovation Solution

A method and system for monitoring NSFs are provided, involving a security controller that receives a high-level security policy, translates it into a low-level policy, configures the NSF, and receives monitoring data including type information such as alarms, events, logs, or counters, which are then transmitted to users or developer management systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive monitoring of NSFs is implemented, then security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring system is segmented into distinct functional modules: policy management module for receiving and translating security policies, monitoring data collection module for gathering alarms/events/logs/counters, data processing module for analyzing monitoring information, and notification module for alerting stakeholders. This segmentation allows comprehensive monitoring while managing complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A security controller acts as an intermediary between NSF instances and the monitoring system. The controller receives monitoring data from NSFs, processes the information according to security policies, and generates notifications. This intermediary layer simplifies the overall system architecture by centralizing the monitoring logic and data flow management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If real-time monitoring data collection is implemented, then security response time is improved, but information processing load increases

Engineering Contradiction:
Improvesecurity response timeVSAvoidinformation processing load
Core Design Contradiction:
Loss of timeVSUse of energy by moving object

Solution Approach 1:

Security policies are pre-configured and stored in the system before monitoring events occur. The policy management module maintains a repository of security rules, thresholds, and notification preferences that are prepared in advance. When monitoring data is received, the system can immediately match it against pre-defined policies without requiring complex real-time analysis, thus reducing processing load while maintaining fast response times.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If detailed monitoring information is collected, then security visibility is improved, but data management complexity increases

Engineering Contradiction:
Improvesecurity visibilityVSAvoiddata management complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The monitoring system implements a universal data model that can represent multiple types of monitoring information (alarms, events, logs, counters) using a common structure. The YANG data model defines standardized schemas for different data types, allowing the system to handle diverse monitoring information uniformly. This universal approach provides comprehensive security visibility while simplifying data management through consistent processing and storage mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11388197B2I2NSF NSF monitoring YANG data model
Publication Date: 2022.07.12 RES & BUSINESS FOUND SUNGKYUNKWAN UNIV
  • US11388197B2 patent drawing
  • US11388197B2 patent drawing
  • US11388197B2 patent drawing

AI summary

An information model for monitoring Network Security Functions (NSF) in an Interface to Network Security Functions (I2NSF) framework is disclosed.