I2NSF Security Controller YANG Model for NSF Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack an efficient method for monitoring Network Security Functions (NSFs) within the Interface to Network Security Functions (I2NSF) framework, which is essential for timely detection of malicious activities and anomalous behavior.
Innovation Solution
A method and system for monitoring NSFs are provided, involving a security controller that receives a high-level security policy, translates it into a low-level policy, configures the NSF, and receives monitoring data including type information such as alarms, events, logs, or counters, which are then transmitted to users or developer management systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive monitoring of NSFs is implemented, then security detection capability is improved, but system complexity increases
Solution Approach 1:
The monitoring system is segmented into distinct functional modules: policy management module for receiving and translating security policies, monitoring data collection module for gathering alarms/events/logs/counters, data processing module for analyzing monitoring information, and notification module for alerting stakeholders. This segmentation allows comprehensive monitoring while managing complexity through modular architecture.
Solution Approach 2:
A security controller acts as an intermediary between NSF instances and the monitoring system. The controller receives monitoring data from NSFs, processes the information according to security policies, and generates notifications. This intermediary layer simplifies the overall system architecture by centralizing the monitoring logic and data flow management.
2Loss of time
If real-time monitoring data collection is implemented, then security response time is improved, but information processing load increases
Solution Approach 1:
Security policies are pre-configured and stored in the system before monitoring events occur. The policy management module maintains a repository of security rules, thresholds, and notification preferences that are prepared in advance. When monitoring data is received, the system can immediately match it against pre-defined policies without requiring complex real-time analysis, thus reducing processing load while maintaining fast response times.
3Loss of information
If detailed monitoring information is collected, then security visibility is improved, but data management complexity increases
Solution Approach 1:
The monitoring system implements a universal data model that can represent multiple types of monitoring information (alarms, events, logs, counters) using a common structure. The YANG data model defines standardized schemas for different data types, allowing the system to handle diverse monitoring information uniformly. This universal approach provides comprehensive security visibility while simplifying data management through consistent processing and storage mechanisms.
Data Source
AI summary
An information model for monitoring Network Security Functions (NSF) in an Interface to Network Security Functions (I2NSF) framework is disclosed.


