Regarding the security policy languages, ANASTACIA selected the HSPL/MSPL to model the security policies for the ANASTACIA project. Then the main security policies to cope with the main goals of the project were identified, like access control, filtering, forwarding, channel protection and specific IoT operational policies. The security policy models were extended to be able to represent specific network and IoT capabilities. Using the new models, the security policies at different levels were defined and instantiated, to be used in the main ANASTACIA use cases.
Detail the High-level Security Policy Language (HSPL) and the Medium-level Security Policy Language (MSPL) as well as the main identified security policies and the policy refinement and translation processes through multiple diagrams and step-by-step workflows for each process has been identified. These processes oversee refining high-level to medium-level security policies and translating medium-level security policies in final security enabler configurations.
ANASTACIA framework covers: (1) a refinement process from High-level Security Language (HSPL) to Medium-level security Policy Language (MSPL), corresponding to h2mservice API; and (2), a translation from Medium-level Security Policy Language (MSPL) to lower-level configurations which will correspond to m2lservice API.
A key innovation of ANASTACIA has been in defining and implementing synergies between SDN controllers (i.e. namely the SDN-based security enforcement algorithms) and NFV MANO (i.e. the security-aware VNF placement algorithms), and that is for the purpose of coordinating security to have an effective impact. Regarding Monitoring and Reaction capabilities of the platform, several areas has been researched:
• Define the architecture of the Monitoring and Reaction Modules of the ANASTACIA platform.
• Analyse the monitoring and reaction capabilities of the technologies brought by the partners.
• Develop the corresponding adaptations of such technologies to meet the project requirements.
• Help the integration of the developed technologies, by defining the interfaced with other components of the ANASTACIA platform.
Within the privacy area, initial research efforts pursued a broad-ranging examination of regional and national legislation which could be of relevance to the DSPS. These efforts led to the identification of specific dispositions in the GDPR, eIDAS regulation, e-privacy directive and swiss regulations which should shape the DSPS’s approach to personal data protection and security certification and to the design of the seal itself. A similar process was followed in the case of technical standards: Following a sweeping examination of standards and recommendations by ISO, ITU, ENISA, NIST and other bodies related to the IoT/CPS ecosystem; several standards were identified as having the potential to support the synthetic DSPS model or to further define the DSPS architecture that should be developed and implemented.
A complete plan for the implementation of use cases has been defined, through the identifying of cases that will examine critical components and features in the ANASTACIA framework. Finally, based on this plan, the use cases have started their implementation phase, with preparation of specific testbeds, and integration of ANASTACIA components.