KUBETEUS: An Intelligent Network Policy Generation Framework for Containers
Bom Kim, Hyeonjun Park, Seungsoo Lee
Abstract
Containers have become the standard for delivering cloud-native services by taking advantage of their scalability, portability, and resource efficiency. However, particularly in network policies, they have also become major targets for various security attacks that exploit misconfigurations and vulnerabilities. Especially in complex cloud-native environments, manually managing network policies is prone to errors, and existing studies that automate policy generation often have limitations in accuracy. In this paper, we present KUBETEUS,a highly automated, intelligent network policy generation framework. Our system operates in an intent-driven manner, enhanced by natural language processing (NLP) and fine-tuned Large Language Models (LLMs), enabling the generation of network policies without needing to understand complex configurations. Furthermore, our system devises a multi-stage validation process to fundamentally prevent misconfigurations in network policy enforcement. The evaluation of KUBETEUS demonstrates its effectiveness, with the most improved fine-tuned LLM achieving a 360% increase in BLEU score and a 233% increase in ROUGE-2 score compared to the baseline model. We believe that the approach presented in this paper is applicable to the wide range of container-native policy platforms in used today, and that its broader adoption will help address more complex security policy generation concerns.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- From Generation to Guarantee: Intent-Based Configuration Update with Verification FeedbackLingqi Guo, Yuhang Yan, Qi Qi, Haifeng Sun et al.INFOCOM 2026
- Hey, Lumi! Using Natural Language for Intent-Based Network ManagementArthur Selle Jacobs, Ricardo J. Pfitscher, Rafael Hengen Ribeiro, Ronaldo A. Ferreira et al.USENIX ATC 2021 · 142 citations
- Intent-Driven Network Management with Multi-Agent LLMs: The Confucius FrameworkZhaodong Wang, Samuel Lin, Guanqing Yan, Soudeh Ghorbani et al.SIGCOMM 2025 · 22 citations
- Beyond Static Pattern Matching? Rethinking Automatic Cryptographic API Misuse Detection in the Era of LLMsYifan Xia, Zichen Xie, Peiyu Liu, Kangjie Lu et al.ISSTA 2025 · 2 citations
- ALPS: Automated Least-Privilege Enforcement for Securing Serverless FunctionsChanghee Shin, Bom Kim, Seungsoo LeeINFOCOM 2026 · 1 citation
