Skip to content
Book Open access

Elastispec: Formalizing Enterprise Firewall Management with Informal and Elastic Specifications

Aug 2026 · Conference on Applications, Technologies, Architectures, and Protocols for Computer Communication · pp. 140-159 · 0 citations · 74 references
Computer Science

TL;DR

Evaluations show that Elastispec is effective in enabling operators to audit their configurations against vendor documents by producing compliance trees, enabling comparative analysis across parallel application deployments, and detecting configuration errors that permit non-compliant traffic.

Abstract

Managing enterprise network firewalls is an ad-hoc process today, where administrators must extract policies relevant to their enterprises from thousands of natural language vendor documents and tailor them to their unique context. In this paper, we present Elastispec, a first step towards principled management of enterprise firewall policies with informal and incomplete specifications. We make three contributions: (i) LLM-assisted formalization of vendor documents into a custom domain specific language that precisely captures the rich choices and options using a multi-step consistency-preserving LLM agent; (ii) mapping the DSL to a concrete network environment by correlating diverse and possibly imperfect enterprise data sources; and (iii) an interactive auditor that cross-checks firewall configurations against the formal but potentially partial specifications and reports potential compliance gaps along with conjectures for human validation. Evaluations with real-world enterprise firewall configurations and popular enterprise application vendor documents show that Elastispec is effective in enabling operators to audit their configurations against vendor documents by producing compliance trees, enabling comparative analysis across parallel application deployments, and detecting configuration errors that permit non-compliant traffic.

Read PDF

Similar papers

Review Aug 2026

TopoIntent: Compiling Security Intent into Executable, Compliance-Checked Network Topologies

TopoIntent is presented, a system that compiles security intent into executable, compliance-checked network topologies, using a schema contract to constrain generation, retrieves reference architectures from a curated template library via dense-vector search, and applies staged fusion for intent-template alignment and...

Xiaokang Qu, Jian-Liang Ma, Z. Fan et al. · 0 citations
Jul 2026

ARCHER: Agentic Rule and Compliance Harness for Executable Regulations

Verifying building compliance requires validating thousands of rules against large Building Information Modeling (BIM) designs, which is laborious, capital-intensive, and unscalable. Existing Automated Compliance Checkers (ACCs) are often difficult to generalize across different scenarios, as they are typically develop...

Chiraag Singh Anand, Xue Wen Tan, L. Teo et al. · 0 citations
Jul 2026

Specification-Driven DevOps for Multi-Service Environments

This study investigates whether a frontier LLM can generate Dockerfiles and Docker Compose configurations for multi-service applications using repository contents without access to developer-authored deployment artifacts and analytically derives a minimal explicit deployment specification for information that cannot be...

Oleg Grynets, Kyrylo Fursov, V. Lyashkevych et al. · 1 citation

SymCert: Verifying SMT-Based Policy Analyses

SymCert is presented, a framework implemented in Lean for building verified SMT-based analyses of Cedar policies that provide a verified symbolic compiler and authorizer for reducing policies to SMT formulas, a hierarchy enforcer for ensuring well-formedness of counterexamples, and a counterex-ample extractor for provi...

Emina Torlak · 0 citations
Conference Aug 2026

Analyzing Structural and Semantic Barriers to Automated Adversary Emulation in Active Directory

Active Directory (AD) underpins enterprise identity management and is among the most heavily targeted assets in modern enterprise networks. When red teams emulate attackers targeting it, they typically chain BloodHound for relationship mapping, Impacket for protocol manipulation, and Responder for credential intercepti...

Anita Ding, Anthony J. Rose, Mark G. Reith · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.