Score
Designs, implements, and evaluates mechanisms that separate and control network traffic flows so that different tenants, services, or components cannot observe or interfere with one another; this includes building and configuring segmentation and enforcement primitives (e.g., VLANs, virtual networks, namespaces, ACLs, firewall rules, routing and rate‑limiting policies) and analyzing their correctness, performance, and failure modes.
This work addresses the vulnerability of data-driven security policies in software-defined networks (SDNs) to overreacting to anomalous traffic, which can lead to misclassification and degrade the performance of machine learning–based intrusion detection systems. To mitigate this issue, the authors propose Safeguard, a novel mechanism that introduces a set of allow rules derived from known benign traffic. These rules operate in conjunction with data-driven policies, enabling coordinated enforcement at the network edge to prevent unintended responses while simultaneously applying firewall rules against confirmed malicious traffic. By integrating this dual-layer approach, Safeguard effectively alleviates overblocking, significantly enhancing the robustness and accuracy of SDN security policies. Experimental evaluation through a prototype implementation demonstrates the efficacy of the proposed mechanism in dynamic SDN environments.
To address the practical challenges of network slicing deployment in real-world transport networks—particularly the difficulty in simultaneously accommodating bursty traffic and guaranteeing end-to-end QoS—this paper proposes an edge-deployed, fine-grained resource control mechanism. Methodologically, we formulate a unified control model integrating elastic bursty-traffic admission, cross-slice bandwidth sharing, and strict QoS constraints, aligned with the IETF network slicing architecture; we further design an edge-intelligent scheduling algorithm and a dynamic bandwidth reservation strategy. Our key contribution lies in the first joint modeling and real-time edge-based coordination of these three critical dimensions, bridging the gap between standard specifications and operational implementation. Experimental evaluation demonstrates a QoS compliance rate exceeding 99.2%, significant suppression of intra-slice burst-induced disturbances, and a 37% improvement in network bandwidth utilization.
Lack of portable Layer-3 (L3) network policy enforcement mechanisms across heterogeneous infrastructures hinders data-plane traffic security and cross-environment policy consistency. Method: We propose a novel paradigm that deeply integrates L3 network policies into the service mesh data plane, building an IP-overlay network atop Kubernetes/Istio. Policy enforcement points (PEPs) perform routing and key-based authorization for access control, while service mesh proxies uniformly enforce policies—eliminating dependence on underlying network capabilities. Contribution: This work presents the first infrastructure-agnostic, portable L3 policy enforcement mechanism. It enables unified L3–L7 policy specification and end-to-end governance. Our prototype introduces less than 1 ms latency overhead while matching the expressiveness of Kubernetes native NetworkPolicy. Experimental evaluation validates consistent, cross-cloud and hybrid-environment policy enforcement feasibility.
This work addresses the challenge of automatically translating high-level service intents into effective Linux traffic control configurations, a task traditionally reliant on manual, low-level operations. The paper presents the first end-to-end framework that converts natural language or declarative intent specifications into standards-compliant Quality of Service (QoS) rules. The approach integrates queueing-theoretic semantic modeling, the LLaMA3 large language model, Active Queue Management (AQM)-guided prompting, and a rule-based validation mechanism to ensure correctness and compliance of the generated configurations. Experimental evaluation on 100 test intents demonstrates that LLaMA3 achieves a semantic similarity of 0.88 and a coverage of 0.87, outperforming baseline models by over 30%. Furthermore, AQM-guided prompting reduces output variability by a factor of three, significantly enhancing consistency and reliability.
本文探讨了在系统连接随时间变化的情况下,如何通过考虑可达性而非仅依赖静态观察来改进防火墙和监控策略的问题。
This study addresses the lack of theoretical understanding regarding the interaction between congestion control algorithms (CCAs) and traffic policers in modern networks, which hinders the rational configuration of policing parameters. It is the first to systematically demonstrate that the interaction dynamics between CCAs and policers—whether based on virtual queues or token buckets—fundamentally differ from those with traffic shapers. The authors develop a formal analytical framework that integrates congestion control theory, virtual queue mechanisms, and token bucket models to derive precise configuration guidelines for key policing parameters, such as virtual queue capacity and assured rate thresholds. This work provides network operators with verifiable and tunable policing strategies, substantially enhancing the efficiency of network resource management.
This study addresses the challenge of evaluating the trustworthiness of automated systems in complex network environments by proposing a five-dimensional “Network Control Intelligence” (NCI) framework. The framework delineates three evolutionary eras of network control and introduces a reference architecture that decouples proposal generation from controlled execution. Emphasizing the synergistic alignment of reasoning capability, verifiability, and authorized execution under large language model (LLM) guidance, it systematically defines, for the first time, the core dimensions of trustworthy autonomous networking. The work not only articulates an integrated paradigm for LLM-enabled network operations and outlines a path toward higher-order autonomy governed by regulatory constraints, but also establishes foundational theoretical principles and design guidelines for secure, governable next-generation network automation.
This study addresses the coordination challenges in in-band SDN control plane deployments with multiple controllers, where controller discovery, state synchronization, and failure recovery must be achieved without expanding switch forwarding state. The authors propose a boundary-switch-based local forwarding graph mechanism that confines inter-domain routing information to boundary devices, preventing state propagation into intermediate domains. In-band control communication is realized using Open vSwitch’s Nicira extensions with NSH encapsulation, and neighbor discovery is accomplished via Controller Advertisement messages. The approach requires no switch firmware modifications and incurs flow table overhead independent of the number of controllers, maintaining constant space complexity. Experiments in a Mininet environment with 96 switches and 5 controllers demonstrate that internal switches exhibit fixed flow table occupancy, enabling network scalability to hundreds of nodes with controller discovery convergence times on the order of seconds.
This work addresses the lack of effective validation mechanisms between high-level management intent and low-level data-plane execution in Intent-Based Networking (IBN) by proposing an Internal Low-level Intent (ILI) telemetry framework. The framework standardizes packet headers into 7-tuple vectors to construct a quantifiable telemetry interface for measuring intent consistency. Analysis of 100.91 million honeypot flow records reveals a “compliance paradox”: while relaxing policy strictness reduces violation counts, intent drift remains largely unchanged, indicating the unreliability of conventional violation metrics. The ILI metric effectively identifies intent deviations and enables closed-loop policy adjustments, demonstrating consistent fidelity to high-level intent across Strict, Balanced, and Permissive policy configurations.
本文提出EvidenceNet解决网络自动化中跨域AI代理操作的验证问题,通过收集和评估来自不同范围的当前观察来确认操作是否达到预期网络状态。