Mikhael Russo
A NILE-to-VEREFOO Translator for Intent-Based Network Security Automation.
Rel. Riccardo Sisto, Fulvio Valenza, Daniele Bringhenti. Politecnico di Torino, Corso di laurea magistrale in Cybersecurity, 2025
|
Preview |
PDF (Tesi_di_laurea)
- Tesi
Licenza: Creative Commons Attribution Non-commercial No Derivatives. Download (3MB) | Preview |
Abstract
The rapid evolution of network infrastructures, driven by paradigms such as Software-Defined Networking (SDN), Network Function Virtualization (NFV), cloud computing, and the Internet of Things (IoT), has significantly increased the complexity of configuration and management tasks. In this context, Intent-Based Networking (IBN) introduces a paradigm shift: it allows operators to express high-level objectives (intents) without specifying their technical implementation. However, a key challenge remains the correct and verifiable translation of these intents into enforceable configurations, especially in the security domain. This thesis investigates this translation problem by focusing on the interoperability between NILE (Network Intent LanguagE), an intermediate and human-readable intent language, and VEREFOO, a framework developed at Politecnico di Torino for the automation and formal verification of network security policies.
After a comparative analysis of the semantics, input, and output models of the two systems, a translation model is proposed to map NILE constructs into VEREFOO's XML-based representation
Relatori
Anno Accademico
Tipo di pubblicazione
Numero di pagine
Corso di laurea
Classe di laurea
URI
![]() |
Modifica (riservato agli operatori) |
