TopoIntent: AI System Compiles Security Intent into Compliance-Checked Network Topologies
A novel system named TopoIntent, described in a preprint on arXiv (2608.13389), tackles the issue of converting business intentions, regulatory standards, and risk assumptions into executable network topologies that comply with regulations. It employs a schema contract to guide the generation process, retrieves reference architectures from a curated template library using dense-vector search, and implements staged fusion for aligning intents with templates and ensuring security. The resulting topologies are evaluated against CIS Controls v8.1.2 safeguards at the topology layer, with any unresolved issues flagged for manual assessment. Structural deficiencies are addressed through additive schema-preserving methods. This research underscores the shortcomings of current NetOps automation tools, which usually function post-design and provide limited assistance in creating structured security topologies from vague natural-language requirements. TopoIntent seeks to fill this gap by automating the initial design phase, enhancing efficiency and compliance in enterprise security architecture.
Key facts
- TopoIntent compiles security intent into executable, compliance-checked network topologies.
- The system uses a schema contract to constrain generation.
- It retrieves reference architectures from a curated template library via dense-vector search.
- Staged fusion is applied for intent-template alignment and security completion.
- Generated topologies are checked against CIS Controls v8.1.2 safeguards.
- Unresolved cases are marked for manual review.
- Structural gaps are repaired through additive schema-preserving operations.
- The preprint is available on arXiv with ID 2608.13389.
Entities
Institutions
- arXiv