Score
Designs and implements policy frameworks, enforcement mechanisms, and deployment/configuration workflows that regulate the flow of traffic across channels — including rules for routing, prioritization, rate limiting, access control, and compliance. Builds the instrumentation and analytics used to measure and audit traffic patterns and governance effectiveness, and analyzes those measurements to tune rules and detect violations.
Lack of portable Layer-3 (L3) network policy enforcement mechanisms across heterogeneous infrastructures hinders data-plane traffic security and cross-environment policy consistency. Method: We propose a novel paradigm that deeply integrates L3 network policies into the service mesh data plane, building an IP-overlay network atop Kubernetes/Istio. Policy enforcement points (PEPs) perform routing and key-based authorization for access control, while service mesh proxies uniformly enforce policies—eliminating dependence on underlying network capabilities. Contribution: This work presents the first infrastructure-agnostic, portable L3 policy enforcement mechanism. It enables unified L3–L7 policy specification and end-to-end governance. Our prototype introduces less than 1 ms latency overhead while matching the expressiveness of Kubernetes native NetworkPolicy. Experimental evaluation validates consistent, cross-cloud and hybrid-environment policy enforcement feasibility.
This work addresses the challenge of automatically translating high-level service intents into effective Linux traffic control configurations, a task traditionally reliant on manual, low-level operations. The paper presents the first end-to-end framework that converts natural language or declarative intent specifications into standards-compliant Quality of Service (QoS) rules. The approach integrates queueing-theoretic semantic modeling, the LLaMA3 large language model, Active Queue Management (AQM)-guided prompting, and a rule-based validation mechanism to ensure correctness and compliance of the generated configurations. Experimental evaluation on 100 test intents demonstrates that LLaMA3 achieves a semantic similarity of 0.88 and a coverage of 0.87, outperforming baseline models by over 30%. Furthermore, AQM-guided prompting reduces output variability by a factor of three, significantly enhancing consistency and reliability.
To address the challenges of complex security control configuration, difficult policy enforcement, and delayed response in networked systems, this paper proposes a Security Capability Model (SCM). The SCM establishes, for the first time, a computable abstract framework integrating information and data models, formally specifying rule semantics, policy parsing mechanisms, and data representations for filtering- and channel-protection–based controls. Leveraging UML/SysML modeling, Model-Driven Engineering (MDE), and a multi-granularity security control description language, the approach enables automated policy refinement, cross-heterogeneous-device (e.g., firewalls, encrypted gateways) configuration generation, and event-driven response. Experimental evaluation demonstrates a threefold improvement in policy deployment timeliness and a 40% increase in configuration accuracy, thereby filling a critical gap in the formal foundations for automated security policy enforcement.
This work addresses the vulnerability of data-driven security policies in software-defined networks (SDNs) to overreacting to anomalous traffic, which can lead to misclassification and degrade the performance of machine learning–based intrusion detection systems. To mitigate this issue, the authors propose Safeguard, a novel mechanism that introduces a set of allow rules derived from known benign traffic. These rules operate in conjunction with data-driven policies, enabling coordinated enforcement at the network edge to prevent unintended responses while simultaneously applying firewall rules against confirmed malicious traffic. By integrating this dual-layer approach, Safeguard effectively alleviates overblocking, significantly enhancing the robustness and accuracy of SDN security policies. Experimental evaluation through a prototype implementation demonstrates the efficacy of the proposed mechanism in dynamic SDN environments.
This work addresses the lack of effective validation mechanisms between high-level management intent and low-level data-plane execution in Intent-Based Networking (IBN) by proposing an Internal Low-level Intent (ILI) telemetry framework. The framework standardizes packet headers into 7-tuple vectors to construct a quantifiable telemetry interface for measuring intent consistency. Analysis of 100.91 million honeypot flow records reveals a “compliance paradox”: while relaxing policy strictness reduces violation counts, intent drift remains largely unchanged, indicating the unreliability of conventional violation metrics. The ILI metric effectively identifies intent deviations and enables closed-loop policy adjustments, demonstrating consistent fidelity to high-level intent across Strict, Balanced, and Permissive policy configurations.
This study addresses the challenge of endowing traditional business processes with intelligent reasoning and adaptive capabilities while preserving the determinism of existing workflow engines. To this end, the authors propose a “workflow suite” mechanism that enables dynamic intervention by embedding a layer of policy-constrained agents at critical control points. They introduce a novel Task-Decision-Flow (TDF) model that defines three types of collaborative agents and integrates the FRAME policy framework to govern large language model (LLM) invocations, thereby harmonizing structural compliance with normative autonomy. Leveraging a hook-based integration architecture, the approach is implemented and validated within the CUGA FLO system using a loan approval case study, demonstrating a balanced synthesis of process determinism and intelligent flexibility.
Third-party APIs are susceptible to regional outages, rate limiting, or quota exhaustion, often leading to user-visible service disruptions. This work proposes a configuration-driven dynamic API routing architecture that decouples routing policies from application logic, enabling runtime vendor switching without redeployment. The architecture formalizes a multidimensional factor model and integrates real-time telemetry, sliding-window health metrics, circuit breakers, bulkhead isolation, and a closed-loop decision engine to automate optimal routing based on performance indicators such as completion rate. Evaluated in an anonymous SMS verification scenario, the system successfully replaces manual intervention and significantly enhances service resilience and availability.
This study addresses the lack of theoretical understanding regarding the interaction between congestion control algorithms (CCAs) and traffic policers in modern networks, which hinders the rational configuration of policing parameters. It is the first to systematically demonstrate that the interaction dynamics between CCAs and policers—whether based on virtual queues or token buckets—fundamentally differ from those with traffic shapers. The authors develop a formal analytical framework that integrates congestion control theory, virtual queue mechanisms, and token bucket models to derive precise configuration guidelines for key policing parameters, such as virtual queue capacity and assured rate thresholds. This work provides network operators with verifiable and tunable policing strategies, substantially enhancing the efficiency of network resource management.