Security Policy Translator for Network Security Functions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing security policy translation methods struggle to effectively convert high-level security policies into low-level policies compatible with Network Security Functions (NSFs) for Interface to Network Security Functions (I2NSF) users, as they lack the necessary specificity and compatibility, requiring users with advanced knowledge to specify detailed information like source IP addresses and website URLs.
Innovation Solution
A method and system for a security policy translator in a security controller that uses Automata theory, specifically Deterministic Finite Automaton (DFA) and Context Free Grammar (CFG), to extract and convert high-level security policies into low-level policies by comparing extracted data with NSF capabilities, utilizing an NSF database for endpoint and capability information, and generating policies compatible with target NSFs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If existing security policy translation methods are used to convert high-level security policies into low-level policies, then the translation process can be performed, but the resulting policies lack specificity and compatibility with Network Security Functions, requiring users to have advanced knowledge to specify detailed information
Solution Approach 1:
The patent introduces a security policy translator as an intermediary component that automatically translates high-level security policies into low-level policies compatible with Network Security Functions. This translator acts as a mediator between the user-friendly high-level policy specification interface and the technical NSF-facing interface, eliminating the need for users to manually specify detailed technical parameters while ensuring compatibility and precision in the translated policies.
2Adaptability or versatility
If high-level security policies are translated into low-level policies without proper translation mechanisms, then users can specify policies at a high level, but the policies cannot be effectively enforced by Network Security Functions
Solution Approach 1:
The security policy translator serves as a critical intermediary that ensures reliable enforcement of high-level policies by automatically converting them into precise low-level policies that Network Security Functions can execute. The translator maintains the adaptability and flexibility of high-level policy specification while guaranteeing enforceability through accurate translation to the NSF-facing interface data model.
Solution Approach 2:
The translation process involves systematic parameter changes where high-level policy parameters are automatically mapped and transformed into corresponding low-level policy parameters required by Network Security Functions. This parameter transformation ensures that the semantic meaning and enforcement requirements are preserved while adapting to the specific data model and capability requirements of target NSFs.
3Manufacturing precision
If users are required to specify detailed information like source IP addresses and website URLs, then the policies can be precise, but users need advanced knowledge making the system difficult to operate
Solution Approach 1:
The security policy translator acts as an intelligent intermediary that automatically extracts and fills in detailed policy parameters such as source IP addresses, destination URLs, and other technical specifications based on the high-level policy intent. This eliminates the burden of manual detailed specification from users while ensuring precision in the translated low-level policies through automated parameter extraction and mapping.
Data Source
AI summary
A method and a device for policy translation of a data converter in a security management system are disclosed.


