KUBETEUS: An Intelligent Network Policy Generation Framework for Containers
Bom Kim, Hyeonjun Park, Seungsoo Lee
摘要
Containers have become the standard for delivering cloud-native services by taking advantage of their scalability, portability, and resource efficiency. However, particularly in network policies, they have also become major targets for various security attacks that exploit misconfigurations and vulnerabilities. Especially in complex cloud-native environments, manually managing network policies is prone to errors, and existing studies that automate policy generation often have limitations in accuracy. In this paper, we present KUBETEUS,a highly automated, intelligent network policy generation framework. Our system operates in an intent-driven manner, enhanced by natural language processing (NLP) and fine-tuned Large Language Models (LLMs), enabling the generation of network policies without needing to understand complex configurations. Furthermore, our system devises a multi-stage validation process to fundamentally prevent misconfigurations in network policy enforcement. The evaluation of KUBETEUS demonstrates its effectiveness, with the most improved fine-tuned LLM achieving a 360% increase in BLEU score and a 233% increase in ROUGE-2 score compared to the baseline model. We believe that the approach presented in this paper is applicable to the wide range of container-native policy platforms in used today, and that its broader adoption will help address more complex security policy generation concerns.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- From Generation to Guarantee: Intent-Based Configuration Update with Verification FeedbackLingqi Guo, Yuhang Yan, Qi Qi, Haifeng Sun 等INFOCOM 2026
- Hey, Lumi! Using Natural Language for Intent-Based Network ManagementArthur Selle Jacobs, Ricardo J. Pfitscher, Rafael Hengen Ribeiro, Ronaldo A. Ferreira 等USENIX ATC 2021 · 被引用 142 次
- Intent-Driven Network Management with Multi-Agent LLMs: The Confucius FrameworkZhaodong Wang, Samuel Lin, Guanqing Yan, Soudeh Ghorbani 等SIGCOMM 2025 · 被引用 22 次
- Beyond Static Pattern Matching? Rethinking Automatic Cryptographic API Misuse Detection in the Era of LLMsYifan Xia, Zichen Xie, Peiyu Liu, Kangjie Lu 等ISSTA 2025 · 被引用 2 次
- ALPS: Automated Least-Privilege Enforcement for Securing Serverless FunctionsChanghee Shin, Bom Kim, Seungsoo LeeINFOCOM 2026 · 被引用 1 次
