arXiv:2604.01627cs.CRcs.AI2026-04

自动将安全意图转化为可部署策略,解决网络设备配置难题。

RefinementEngine: Automating Intent-to-Device Filtering Policy Deployment under Network Constraints

  • 基于网络拓扑和威胁情报,自动推导出可执行的配置规则。
  • 在真实场景中验证了策略正确性和快速适应新威胁的能力。
  • 适合安全运维人员和自动化安全系统开发者使用。

将安全意图转化为可部署的网络执行规则,并在不断演变的网络威胁下保持其有效性,目前在多数安全运营中心(SOC)仍依赖人工操作。在大规模异构网络中,这一过程因拓扑相关的可达性限制和设备特有的安全控制能力而更加复杂,导致配置缓慢、易出错且频繁出现误配置。本文提出 RefinementEngine,一个将高层安全意图自动精炼为低层可部署配置的引擎。给定网络拓扑、设备及可用安全控制,结合高层安全意图与网络安全威胁情报(CTI)报告,RefinementEngine 能自动生成实现目标意图、应对已报告威胁并可直接部署于目标安全设备的配置。该方法通过实际案例在来自真实 CTI 报告的包过滤和网页过滤策略上进行了验证,证明了其正确性、实用性和对新数据的适应能力。

原文摘要 · Abstract (English)

Translating security intent into deployable network enforcement rules and maintaining their effectiveness despite evolving cyber threats remains a largely manual process in most Security Operations Centers (SOCs). In large and heterogeneous networks, this challenge is complicated by topology-dependent reachability constraints and device-specific security control capabilities, making the process slow, error-prone, and a recurring source of misconfigurations. This paper presents RefinementEngine, an engine that automates the refinement of high-level security intents into low-level, deployment-ready configurations. Given a network topology, devices, and available security controls, along with high-level intents and Cyber Threat Intelligence (CTI) reports, RefinementEngine automatically generates settings that implement the desired intent, counter reported threats, and can be directly deployed on target security controls. The proposed approach is validated through real-world use cases on packet and web filtering policies derived from actual CTI reports, demonstrating both correctness, practical applicability, and adaptability to new data.

安全自动化策略生成威胁情报

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。