I2NSF YANG Data Model for Network Security Policy Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems lack a standardized interface for managing heterogeneous Network Security Functions (NSFs), making it difficult to define and enforce security policies across different vendors and networks, especially in managing network traffic and mitigating attacks effectively.
Innovation Solution
The proposed solution involves designing a YANG data model and information model for an NSF-facing interface within the I2NSF framework, which allows for the creation and transmission of low-level security policies to multiple NSFs, including blocking SNS access, malicious VoIP/VoLTE packets, and mitigating HTTP/HTTPS floods, through a network operator management system connected to an I2NSF NSF-facing interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a standardized interface for managing heterogeneous Network Security Functions is implemented, then the ease of operation and management of security policies is improved, but the device complexity increases due to the need for standardized protocols and data models
Solution Approach 1:
The patent implements a universal YANG data model that can manage multiple types of network security functions (firewalls, intrusion detection systems, DDoS protection) through a single standardized interface. This universal model allows different vendor NSFs to be managed uniformly, improving ease of operation while the standardization itself introduces structural complexity
Solution Approach 2:
The patent introduces an intermediary management system that sits between the network operator and heterogeneous NSFs. This intermediary translates high-level security policies into vendor-specific configurations, simplifying operator tasks while adding complexity to the overall system architecture through the intermediary layer
2Productivity
If automated policy transmission to multiple NSFs is implemented, then the productivity of security policy deployment is improved, but the device complexity increases due to the automated management system requirements
Solution Approach 1:
The patent implements preliminary action by pre-defining YANG data models and policy templates that can be automatically instantiated and deployed across multiple NSFs. This allows security policies to be prepared in advance and rapidly deployed when needed, improving productivity while the pre-configured automated system adds complexity
Solution Approach 2:
The patent uses copying mechanisms where a single security policy definition in the standardized YANG model can be replicated and transmitted to multiple NSFs simultaneously. This copying capability dramatically improves deployment productivity, but requires complex automated management infrastructure to handle the replication and distribution
Data Source
AI summary
The present disclosure provides a system and method of providing a security service by means of a network operator management system in a security management system, the method including receiving a high-level first security policy from an I2NSF (interface to Network Security Functions) user; receiving an available security service from a developer's management system; creating a low-level second security policy corresponding to the first security policy on the basis of the security service; and transmitting a packet including the second security policy for setting the created second security policy to each of a plurality of NSFs (Network Security Function) to an NSF instance, wherein the network operator management system and the NSFs are respectively connect to an I2NSF NSF-laving interface, and the second security policy includes at least one or more of 1) blocking SNS access during business hours, 2) blocking a malicious VoIP (Voice over Internet Protocol) or a malicious VoCN (Voice over Cellular Network) packet, or 3) mitigating flood of http and https for a company web server.


