I2NSF Analytics YANG Model for Timely Security Policy Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data models for analytics interfaces between an Interface to Network Security Functions (I2NSF) analyzer and a security controller in a network functions virtualization (NFV) environment are inadequate for timely responding to issues detected by network security functions (NSF) providing security services.

Innovation Solution

A YANG data model is introduced for an analytics interface that enables the I2NSF analyzer to receive monitoring data from NSFs, analyze it using machine learning, and generate new security policies or feedback information, which are then provided to the security controller via an analytics interface to automate security management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional data model is used for the analytics interface between I2NSF analyzer and security controller, then the system structure is simple, but the system cannot timely respond to problems detected by network security functions

Engineering Contradiction:
Improvetimely response capabilityVSAvoiddata model complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the analytics interface into distinct YANG data model components including problem information, feedback information, and policy reconfiguration elements. This structured segmentation enables timely and accurate response to detected problems while maintaining manageable complexity through modular organization of security analytics data

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces specific parameters and attributes in the YANG data model such as problem detection timestamps, feedback information structures, and policy reconfiguration parameters. These parameter changes enable the system to capture and respond to security events with appropriate timing and detail without excessive complexity

Inventive Principle:
Principle #35Parameter changes

2Productivity

If manual security policy management is used, then the system complexity is low, but the productivity and responsiveness to security threats are reduced

Engineering Contradiction:
Improvesecurity management efficiencyVSAvoidautomated policy generation
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The patent implements a feedback mechanism where the I2NSF analyzer receives monitoring data from network security functions, analyzes problems detected, generates feedback information, and automatically creates policy reconfigurations. This automated feedback loop significantly improves security management productivity while maintaining controlled automation through the YANG data model framework

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables self-service automation where the I2NSF analyzer autonomously processes security monitoring data, identifies problems, generates appropriate feedback information, and produces policy reconfigurations without manual intervention. This self-service capability enhances productivity while the structured YANG model ensures automation remains manageable and auditable

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive monitoring data collection is implemented, then the measurement precision of security problems is improved, but the loss of time for data processing increases

Engineering Contradiction:
Improveproblem detection accuracyVSAvoiddata analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts only the essential problem information and feedback elements needed for timely security response through the YANG data model. By taking out only the critical data elements required for policy reconfiguration rather than processing all monitoring data comprehensively, the system maintains high measurement precision while reducing data processing time loss

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12375528B2Method and apparatus for security management based on I2NSF analytics interface YANG data model
Publication Date: 2025.07.29 RES & BUSINESS FOUND SUNGKYUNKWAN UNIV
  • US12375528B2 patent drawing
  • US12375528B2 patent drawing
  • US12375528B2 patent drawing

AI summary

The present disclosure relates to a data model for an analytics interface between an Interface to Network Security Functions (I2NSF) analyzer and a security controller in a security management system. A method of performing a security management by the I2NSF analyzer includes receiving monitoring data from at least one network security function (NSF) providing a security service, analyzing the received monitoring data to generate a new security policy or feedback information, and providing the generated new security policy or feedback information to the security controller.