Natural Language Interface for Firewall Configuration

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Taghiyev, F., Aslanbayli, A.
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909957139464192
author Taghiyev, F.
Aslanbayli, A.
author_facet Taghiyev, F.
Aslanbayli, A.
contents This paper presents the design and prototype implementation of a natural language interface for configuring enterprise firewalls. The framework allows administrators to express access control policies in plain language, which are then translated into vendor specific configurations. A compact schema bound intermediate representation separates human intent from device syntax and in the current prototype compiles to Palo Alto PAN OS command line configuration while remaining extensible to other platforms. Large language models are used only as assistive parsers that generate typed intermediate representation objects, while compilation and enforcement remain deterministic. The prototype integrates three validation layers, namely a static linter that checks structural and vendor specific constraints, a safety gate that blocks overly permissive rules such as any to any allows, and a Batfish based simulator that validates configuration syntax and referential integrity against a synthetic device model. The paper describes the architecture, implementation, and test methodology on synthetic network context datasets and discusses how this approach can evolve into a scalable auditable and human centered workflow for firewall policy management.
format Preprint
id arxiv_https___arxiv_org_abs_2512_10789
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Natural Language Interface for Firewall Configuration
Taghiyev, F.
Aslanbayli, A.
Networking and Internet Architecture
Artificial Intelligence
C.2.3; C.2.6; D.2.4; D.2.11; I.2.7; K.6.5
This paper presents the design and prototype implementation of a natural language interface for configuring enterprise firewalls. The framework allows administrators to express access control policies in plain language, which are then translated into vendor specific configurations. A compact schema bound intermediate representation separates human intent from device syntax and in the current prototype compiles to Palo Alto PAN OS command line configuration while remaining extensible to other platforms. Large language models are used only as assistive parsers that generate typed intermediate representation objects, while compilation and enforcement remain deterministic. The prototype integrates three validation layers, namely a static linter that checks structural and vendor specific constraints, a safety gate that blocks overly permissive rules such as any to any allows, and a Batfish based simulator that validates configuration syntax and referential integrity against a synthetic device model. The paper describes the architecture, implementation, and test methodology on synthetic network context datasets and discusses how this approach can evolve into a scalable auditable and human centered workflow for firewall policy management.
title Natural Language Interface for Firewall Configuration
topic Networking and Internet Architecture
Artificial Intelligence
C.2.3; C.2.6; D.2.4; D.2.11; I.2.7; K.6.5
url https://arxiv.org/abs/2512.10789