arXiv:2608.13389cs.AIcs.CR2026-08

将安全需求自动转化为可执行且合规的网络拓扑结构。

TopoIntent: Compiling Security Intent into Executable, Compliance-Checked Network Topologies

论文配图:TopoIntent: Compiling Security Intent into Executable, Compliance-Checked Network Topologies
图 1 · 摘自论文原文
  • 用模板匹配和分阶段融合,从自然语言需求生成安全拓扑。
  • 修复后拓扑对CIS控制项的满足率从0.78提升至1.00。
  • 适合需要自动化合规网络设计的企业与安全团队。

企业安全拓扑设计需将业务意图、监管要求和风险假设转化为区域、边界设备、区域间路径及访问控制策略。现有NetOps工具多在设计定型后运行,难以从模糊的自然语言需求生成结构化安全拓扑。我们提出TopoIntent系统,将安全意图编译为可执行、合规校验的网络拓扑。该系统采用模式契约约束生成过程,通过密集向量搜索从精选模板库中检索参考架构,并应用分阶段融合实现意图-模板对齐与安全补全。生成拓扑基于可见于拓扑层的CIS Controls v8.1.2防护措施进行合规检查,未解决案例标记供人工复核。结构缺口通过保持模式的增补编辑修复。最终拓扑导出为Mininet脚本,包含内核级iptables ACL,支持可执行的可达性及允许/拒绝测试。因该任务无公开基准,我们构建了评估集:检索集含22个模板与44个合成意图(5种场景),保留集含7个模板与14个来自金融与政府场景的意图(未用于检索)。在保留集上,增补修复使拓扑层可见的CIS满足率从0.78提升至1.00,平均不足1.5轮;一次反馈后ACL策略通过率从0.78升至0.88。

原文摘要 · Abstract (English)

Enterprise security topology design requires translating business intent, regulatory requirements, and risk assumptions into zones, boundary devices, inter-zone paths, and access-control policies. Existing NetOps automation tools mainly operate after this design is fixed, providing limited support for generating structured security topologies from underspecified natural-language requirements. We present TopoIntent, a system that compiles security intent into executable, compliance-checked network topologies. It uses a schema contract to constrain generation, retrieves reference architectures from a curated template library via dense-vector search, and applies staged fusion for intent-template alignment and security completion. The generated topology is checked against CIS Controls v8.1.2 safeguards visible at the topology layer, while unresolved cases are marked for manual review. Structural gaps are repaired through additive schema-preserving edits. The final topology is exported to Mininet scripts with kernel-level iptables ACLs, enabling executable reachability and allow/deny tests. Because no public benchmark exists for this requirement-to-topology task, we construct an evaluation set from reference security architecture diagrams. The retrieval set contains 22 templates and 44 synthetic intents across five scenarios, while the held-out set contains 7 templates and 14 intents from finance and government scenarios excluded from retrieval. On the held-out set, additive repair improves topology-visible CIS satisfaction from 0.78 to 1.00 in fewer than 1.5 rounds on average, and one feedback round raises the post-ACL policy pass rate from 0.78 to 0.88.

网络拓扑安全合规自动化设计

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。