@techreport{yang-i2nsf-security-policy-translation-16, number = {draft-yang-i2nsf-security-policy-translation-16}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-yang-i2nsf-security-policy-translation/16/}, author = {Jaehoon Paul Jeong and Patrick Lingga and Jinhyuk Yang}, title = {{Guidelines for Security Policy Translation in Interface to Network Security Functions}}, pagetotal = 47, year = 2024, month = feb, day = 7, abstract = {This document proposes the guidelines for security policy translation in Interface to Network Security Functions (I2NSF) Framework. When I2NSF User delivers a high-level security policy for a security service, Security Policy Translator in Security Controller translates it into a low-level security policy for Network Security Functions (NSFs). For this security policy translation, this document specifies the relation between a high-level security policy based on the Consumer-Facing Interface YANG data model and a low-level security policy based on the NSF-Facing Interface YANG data model. Also, it describes an architecture of a security policy translator along with an NSF database, and the process of security policy translation with the NSF database.}, }