arXiv · 2604.01627
RefinementEngine: Automating Intent-to-Device Filtering Policy Deployment under Network Constraints
Abstract
Translating security intent into deployable network enforcement rules and maintaining their effectiveness despite evolving cyber threats remains a largely manual process in most Security Operations Centers (SOCs). In large and heterogeneous networks, this challenge is complicated by topology-dependent reachability constraints and device-specific security control capabilities, making the process slow, error-prone, and a recurring source of misconfigurations. This paper presents RefinementEngine, an engine that automates the refinement of high-level security intents into low-level, deployment-ready configurations. Given a network topology, devices, and available security controls, along with high-level intents and Cyber Threat Intelligence (CTI) reports, RefinementEngine automatically generates settings that implement the desired intent, counter reported threats, and can be directly deployed on target security controls. The proposed approach is validated through real-world use cases on packet and web filtering policies derived from actual CTI reports, demonstrating both correctness, practical applicability, and adaptability to new data.
Explore related subjects
Keep this discovery
Davide Colaiacomo, Chiara Bonfanti, Cataldo Basile. 2026-04-02. RefinementEngine: Automating Intent-to-Device Filtering Policy Deployment under Network Constraints. https://arxiv.org/abs/2604.01627
Cite the original work for its findings. Save a collection to share your selection of sources.