Mikhael Russo
A NILE-to-VEREFOO Translator for Intent-Based Network Security Automation.
Rel. Riccardo Sisto, Fulvio Valenza, Daniele Bringhenti. Politecnico di Torino, Corso di laurea magistrale in Cybersecurity, 2025
|
PDF (Tesi_di_laurea)
- Tesi
Licenza: Creative Commons Attribution Non-commercial No Derivatives. Download (3MB) | Preview |
| Abstract: |
The rapid evolution of network infrastructures, driven by paradigms such as Software-Defined Networking (SDN), Network Function Virtualization (NFV), cloud computing, and the Internet of Things (IoT), has significantly increased the complexity of configuration and management tasks. In this context, Intent-Based Networking (IBN) introduces a paradigm shift: it allows operators to express high-level objectives (intents) without specifying their technical implementation. However, a key challenge remains the correct and verifiable translation of these intents into enforceable configurations, especially in the security domain. This thesis investigates this translation problem by focusing on the interoperability between NILE (Network Intent LanguagE), an intermediate and human-readable intent language, and VEREFOO, a framework developed at Politecnico di Torino for the automation and formal verification of network security policies. After a comparative analysis of the semantics, input, and output models of the two systems, a translation model is proposed to map NILE constructs into VEREFOO's XML-based representation. A prototype translator has been implemented to automate this process, enabling the conversion of NILE intents into valid VEREFOO input files. The tool has been validated through a series of case studies on different network topologies. The results confirm the feasibility of semantic translation as a bridge between intent-based specification and automated verification frameworks. This work represents a step toward the development of intent-driven network security systems that are more accessible, reliable, and less dependent on specialized expertise, paving the way for future research on AI-assisted intent interpretation and adaptive security automation. |
|---|---|
| Relatori: | Riccardo Sisto, Fulvio Valenza, Daniele Bringhenti |
| Anno accademico: | 2025/26 |
| Tipo di pubblicazione: | Elettronica |
| Numero di pagine: | 90 |
| Soggetti: | |
| Corso di laurea: | Corso di laurea magistrale in Cybersecurity |
| Classe di laurea: | Nuovo ordinamento > Laurea magistrale > LM-32 - INGEGNERIA INFORMATICA |
| Aziende collaboratrici: | NON SPECIFICATO |
| URI: | http://webthesis.biblio.polito.it/id/eprint/38705 |
![]() |
Modifica (riservato agli operatori) |



Licenza Creative Commons - Attribuzione 3.0 Italia