Elastispec: Formalizing Enterprise Firewall Management with Informal and Elastic Specifications
Chenan Wen, Yizhan Qing, Curt P. Jansen, Xiaokang Qiu, Sanjay G. Rao
摘要
Managing enterprise network firewalls is an ad-hoc process today, where administrators must extract policies relevant to their enterprises from thousands of natural language vendor documents and tailor them to their unique context. In this paper, we present Elastispec, a first step towards principled management of enterprise firewall policies with informal and incomplete specifications. We make three contributions: (i) LLM-assisted formalization of vendor documents into a custom domain specific language that precisely captures the rich choices and options using a multi-step consistency-preserving LLM agent; (ii) mapping the DSL to a concrete network environment by correlating diverse and possibly imperfect enterprise data sources; and (iii) an interactive auditor that cross-checks firewall configurations against the formal but potentially partial specifications and reports potential compliance gaps along with conjectures for human validation. Evaluations with real-world enterprise firewall configurations and popular enterprise application vendor documents show that Elastispec is effective in enabling operators to audit their configurations against vendor documents by producing compliance trees, enabling comparative analysis across parallel application deployments, and detecting configuration errors that permit non-compliant traffic.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Hey, Lumi! Using Natural Language for Intent-Based Network ManagementArthur Selle Jacobs, Ricardo J. Pfitscher, Rafael Hengen Ribeiro, Ronaldo A. Ferreira 等USENIX ATC 2021 · 被引用 142 次
- ANTEATER: A Filter-then-Scrutinize Architecture for End-to-End Attack InvestigationYiming Ren, Haoqiang Wang, Linghao Li, Haoyang Chen 等SIGMOD 2026
- Expecto: Extracting Formal Specifications from Natural Language Description for Trustworthy OraclesDongjae Lee, Kihong HeoPLDI 2026
- ROSpec: A Domain-Specific Language for ROS-Based Robot SoftwarePaulo Canelas, Bradley R. Schmerl, Alcides Fonseca, Christopher Steven TimperleyOOPSLA 2025 · 被引用 2 次
- KUBETEUS: An Intelligent Network Policy Generation Framework for ContainersBom Kim, Hyeonjun Park, Seungsoo LeeINFOCOM 2025 · 被引用 4 次
