TopoIntent:将安全意图编译为可执行、合规性检查的网络拓扑结构
TopoIntent: Compiling Security Intent into Executable, Compliance-Checked Network Topologies
浏览论文内容
中文总结 AI 辅助
TopoIntent系统通过模式契约、向量搜索和分阶段融合将安全意图编译为合规可执行拓扑,经评估其修复后CIS满意度与ACL通过率均显著提升。
中文摘要 AI 辅助
企业安全拓扑设计需要将业务意图、监管要求和风险假设转换为安全区域、边界设备、区域间路径以及访问控制策略。现有的NetOps自动化工具主要在该设计确定后才运行,对从欠规范的自然语言需求生成结构化安全拓扑结构的支持有限。本文提出TopoIntent系统,其可将安全意图编译为可执行、经过合规性检查的网络拓扑结构。该系统使用模式契约约束生成过程,通过密集向量搜索从精选模板库中检索参考架构,并应用分阶段融合技术实现意图-模板对齐与安全完善。生成的拓扑结构会对照CIS Controls v8.1.2中拓扑层可见的防护措施进行检查,未解决的案例会标记为手动审查。结构缺口通过保留模式的增量编辑进行修复,最终拓扑结构会导出为带有内核级iptables ACL的Mininet脚本,支持可执行的可达性测试及允许/拒绝测试。由于该需求到拓扑结构任务不存在公开基准,本文从参考安全架构图构建了评估集:检索集包含5个场景下的22个模板和44个合成意图,保留集包含检索时排除的金融和政府场景中的7个模板和14个意图。在保留集上,增量修复使拓扑可见的CIS满意度平均在少于1.5轮内从0.78提升至1.00,一次反馈轮次使ACL后的策略通过率从0.78提升至0.88。
英文摘要
Enterprise security topology design requires translating business intent, regulatory requirements, and risk assumptions into zones, boundary devices, inter-zone paths, and access-control policies. Existing NetOps automation tools mainly operate after this design is fixed, providing limited support for generating structured security topologies from underspecified natural-language requirements. We present TopoIntent, a system that compiles security intent into executable, compliance-checked network topologies. It uses a schema contract to constrain generation, retrieves reference architectures from a curated template library via dense-vector search, and applies staged fusion for intent-template alignment and security completion. The generated topology is checked against CIS Controls v8.1.2 safeguards visible at the topology layer, while unresolved cases are marked for manual review. Structural gaps are repaired through additive schema-preserving edits. The final topology is exported to Mininet scripts with kernel-level iptables ACLs, enabling executable reachability and allow/deny tests. Because no public benchmark exists for this requirement-to-topology task, we construct an evaluation set from reference security architecture diagrams. The retrieval set contains 22 templates and 44 synthetic intents across five scenarios, while the held-out set contains 7 templates and 14 intents from finance and government scenarios excluded from retrieval. On the held-out set, additive repair improves topology-visible CIS satisfaction from 0.78 to 1.00 in fewer than 1.5 rounds on average, and one feedback round raises the post-ACL policy pass rate from 0.78 to 0.88.
发表机构
- University of Science and Technology of China(中国科学技术大学)
- Topsec Technologies Group Inc.(天融信科技集团股份有限公司)
机构由 AI 辅助整理,请以论文原文为准。