Security Policy Translator for Network Security Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing security policy translation methods struggle to effectively convert high-level security policies into low-level policies compatible with Network Security Functions (NSFs) for Interface to Network Security Functions (I2NSF) users, as they lack the necessary specificity and compatibility, requiring users with advanced knowledge to specify detailed information like source IP addresses and website URLs.

Innovation Solution

A method and system for a security policy translator in a security controller that uses Automata theory, specifically Deterministic Finite Automaton (DFA) and Context Free Grammar (CFG), to extract and convert high-level security policies into low-level policies by comparing extracted data with NSF capabilities, utilizing an NSF database for endpoint and capability information, and generating policies compatible with target NSFs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If existing security policy translation methods are used to convert high-level security policies into low-level policies, then the translation process can be performed, but the resulting policies lack specificity and compatibility with Network Security Functions, requiring users to have advanced knowledge to specify detailed information

Engineering Contradiction:
Improveease of specifying security policiesVSAvoidspecificity of translated policies
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent introduces a security policy translator as an intermediary component that automatically translates high-level security policies into low-level policies compatible with Network Security Functions. This translator acts as a mediator between the user-friendly high-level policy specification interface and the technical NSF-facing interface, eliminating the need for users to manually specify detailed technical parameters while ensuring compatibility and precision in the translated policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If high-level security policies are translated into low-level policies without proper translation mechanisms, then users can specify policies at a high level, but the policies cannot be effectively enforced by Network Security Functions

Engineering Contradiction:
Improveflexibility in policy specificationVSAvoidenforceability of policies
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security policy translator serves as a critical intermediary that ensures reliable enforcement of high-level policies by automatically converting them into precise low-level policies that Network Security Functions can execute. The translator maintains the adaptability and flexibility of high-level policy specification while guaranteeing enforceability through accurate translation to the NSF-facing interface data model.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The translation process involves systematic parameter changes where high-level policy parameters are automatically mapped and transformed into corresponding low-level policy parameters required by Network Security Functions. This parameter transformation ensures that the semantic meaning and enforcement requirements are preserved while adapting to the specific data model and capability requirements of target NSFs.

Inventive Principle:
Principle #35Parameter changes

3Manufacturing precision

If users are required to specify detailed information like source IP addresses and website URLs, then the policies can be precise, but users need advanced knowledge making the system difficult to operate

Engineering Contradiction:
Improveprecision of policy detailsVSAvoidease of use for I2NSF users
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The security policy translator acts as an intelligent intermediary that automatically extracts and fills in detailed policy parameters such as source IP addresses, destination URLs, and other technical specifications based on the high-level policy intent. This eliminates the burden of manual detailed specification from users while ensuring precision in the translated low-level policies through automated parameter extraction and mapping.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11632402B2Security policy translation in interface to network security functions
Publication Date: 2023.04.18 RES & BUSINESS FOUND SUNGKYUNKWAN UNIV
  • US11632402B2 patent drawing
  • US11632402B2 patent drawing
  • US11632402B2 patent drawing

AI summary

A method and a device for policy translation of a data converter in a security management system are disclosed.