TopoIntent: Compiling Security Intent into Executable, Compliance-Checked Network Topologies· TopoIntent:将安全意图编译为可执行的合规网络拓扑
Enterprise security topology design requires translating business intent, regulatory requirements, and risk assumptions into zones, boundary devices, inter-zone paths, and access-control policies. Existing NetOps automation tools mainly operate after this design is fixed, providing limited support for generating structured security topologies from underspecified natural-language requirements. We present TopoIntent, a system that compiles security intent into executable, compliance-checked network topologies. It uses a schema contract to constrain generation, retrieves reference architectures from a curated template library via dense-vector search, and applies staged fusion for intent-template alignment and security completion. The generated topology is checked against CIS Controls v8.1.2 s
将安全意图转化为可执行的合规网络拓扑
- 核心方法
- 使用模式合约约束生成过程,通过密集向量搜索从模板库检索参考架构,并应用分阶段融合以实现意图与模板对齐和安全补全
- 适合谁读
- 研究者、工程师、产品经理
- 要解决的问题
- 现有网络操作自动化工具在设计固定后才发挥作用,缺乏从不明确的自然语言需求生成结构化安全拓扑的支持
- 关键实验
- 关键实验包括对生成的拓扑进行 CIS Controls v8.1.2 标准的合规性检查
- 主要贡献
- 提出 TopoIntent 系统,能够将安全意图编译为可执行且合规的网络拓扑
- 意义与局限
- 该系统提高了企业安全拓扑设计的自动化水平,减少了人为错误,但可能对非常规或高度定制化的需求支持不足