I2NSF YANG Data Model for Network Security Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems lack a standardized interface for managing heterogeneous Network Security Functions (NSFs), making it difficult to define and enforce security policies across different vendors and networks, especially in managing network traffic and mitigating attacks effectively.

Innovation Solution

The proposed solution involves designing a YANG data model and information model for an NSF-facing interface within the I2NSF framework, which allows for the creation and transmission of low-level security policies to multiple NSFs, including blocking SNS access, malicious VoIP/VoLTE packets, and mitigating HTTP/HTTPS floods, through a network operator management system connected to an I2NSF NSF-facing interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a standardized interface for managing heterogeneous Network Security Functions is implemented, then the ease of operation and management of security policies is improved, but the device complexity increases due to the need for standardized protocols and data models

Engineering Contradiction:
Improvemanagement of security policiesVSAvoidstandardized interface structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal YANG data model that can manage multiple types of network security functions (firewalls, intrusion detection systems, DDoS protection) through a single standardized interface. This universal model allows different vendor NSFs to be managed uniformly, improving ease of operation while the standardization itself introduces structural complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary management system that sits between the network operator and heterogeneous NSFs. This intermediary translates high-level security policies into vendor-specific configurations, simplifying operator tasks while adding complexity to the overall system architecture through the intermediary layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automated policy transmission to multiple NSFs is implemented, then the productivity of security policy deployment is improved, but the device complexity increases due to the automated management system requirements

Engineering Contradiction:
Improvesecurity policy deploymentVSAvoidautomated management system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-defining YANG data models and policy templates that can be automatically instantiated and deployed across multiple NSFs. This allows security policies to be prepared in advance and rapidly deployed when needed, improving productivity while the pre-configured automated system adds complexity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying mechanisms where a single security policy definition in the standardized YANG model can be replicated and transmitted to multiple NSFs simultaneously. This copying capability dramatically improves deployment productivity, but requires complex automated management infrastructure to handle the replication and distribution

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11792227B2I2NSF network security function facing interface YANG data model
Publication Date: 2023.10.17 RES & BUSINESS FOUND SUNGKYUNKWAN UNIV
  • US11792227B2 patent drawing
  • US11792227B2 patent drawing
  • US11792227B2 patent drawing

AI summary

The present disclosure provides a system and method of providing a security service by means of a network operator management system in a security management system, the method including receiving a high-level first security policy from an I2NSF (interface to Network Security Functions) user; receiving an available security service from a developer's management system; creating a low-level second security policy corresponding to the first security policy on the basis of the security service; and transmitting a packet including the second security policy for setting the created second security policy to each of a plurality of NSFs (Network Security Function) to an NSF instance, wherein the network operator management system and the NSFs are respectively connect to an I2NSF NSF-laving interface, and the second security policy includes at least one or more of 1) blocking SNS access during business hours, 2) blocking a malicious VoIP (Voice over Internet Protocol) or a malicious VoCN (Voice over Cellular Network) packet, or 3) mitigating flood of http and https for a company web server.