RefinementEngine: Automating Intent-to-Device Filtering Policy Deployment under Network Constraints
Davide Colaiacomo, Chiara Bonfanti, Cataldo Basile

TL;DR
RefinementEngine automates converting high-level security intents into deployable network configurations, considering topology, device capabilities, and threat reports, reducing manual effort and errors.
Contribution
The paper introduces RefinementEngine, a system that automates intent refinement into deployment-ready configurations using network topology and threat intelligence.
Findings
Successfully applied to real-world packet and web filtering policies.
Demonstrated correctness and practical applicability.
Adaptable to new threat data and network changes.
Abstract
Translating security intent into deployable network enforcement rules and maintaining their effectiveness despite evolving cyber threats remains a largely manual process in most Security Operations Centers (SOCs). In large and heterogeneous networks, this challenge is complicated by topology-dependent reachability constraints and device-specific security control capabilities, making the process slow, error-prone, and a recurring source of misconfigurations. This paper presents RefinementEngine, an engine that automates the refinement of high-level security intents into low-level, deployment-ready configurations. Given a network topology, devices, and available security controls, along with high-level intents and Cyber Threat Intelligence (CTI) reports, RefinementEngine automatically generates settings that implement the desired intent, counter reported threats, and can be directly…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
