{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T16:08:38Z","timestamp":1783613318812,"version":"3.55.0"},"reference-count":35,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T00:00:00Z","timestamp":1760659200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T00:00:00Z","timestamp":1760659200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100013000","name":"Politecnico di Torino","doi-asserted-by":"crossref","id":[{"id":"10.13039\/100013000","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Netw Syst Manage"],"published-print":{"date-parts":[[2026,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>The computing continuum is a revolutionary cloud paradigm that integrates edge, fog, and cloud layers into a cohesive distributed system of interconnected devices, enabling seamless resource sharing across heterogeneous environments and administrative domains. Its interwoven nature introduces novel challenges, including enforcing proper network isolation between workloads by managing all possible communications. Existing solutions are inadequate as they fail to address the dynamicity and heterogeneity of the computing continuum, exposing users to security risks like cross-tenant interference or side-channel attacks. To address these security challenges, this paper proposes a security solution to automate the configuration of network isolation across the computing continuum. The solution facilitates the enforcement of advanced security patterns, such as zero trust and least privilege, across the several cloud layers involved in the continuum. It employs an intent-based approach, enabling users to specify security requirements in an intuitive, high-level language. The process relies on two core phases: smart verification and harmonization, followed by translation. Their design aims to ensure consistency in the defined intents and adaptability in addressing the evolving nature of the continuum, by simplifying the configuration of advanced security patterns and providing tenants with fine-grained control over network isolation. The approach was implemented in Kubernetes, demonstrating its effectiveness in automating the enforcement of user-defined intents via Kubernetes Network Policies, a common mechanism for network isolation in Kubernetes. The developed implementation was validated both qualitatively in a comprehensive use case, confirming its effectiveness for security management, and quantitatively to assess the performance of the different phases of the process.<\/jats:p>","DOI":"10.1007\/s10922-025-09986-1","type":"journal-article","created":{"date-parts":[[2025,10,17]],"date-time":"2025-10-17T04:35:44Z","timestamp":1760675744000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Intent-Driven Network Isolation for the Cloud Computing Continuum"],"prefix":"10.1007","volume":"34","author":[{"given":"Francesco","family":"Pizzato","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daniele","family":"Bringhenti","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Riccardo","family":"Sisto","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fulvio","family":"Valenza","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,10,17]]},"reference":[{"issue":"1","key":"9986_CR1","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1007\/S10922-024-09896-8","volume":"33","author":"AR Enciso","year":"2025","unstructured":"Enciso, A.R., Murcia, J.M.B., Zarca, A.M., Skarmeta-G\u00f3mez, A.F.: Dynamic multi-method allocation for intent-based security orchestration. J. Netw. Syst. Manag. 33(1), 21 (2025). https:\/\/doi.org\/10.1007\/S10922-024-09896-8","journal-title":"J. Netw. Syst. Manag."},{"key":"9986_CR2","doi-asserted-by":"publisher","unstructured":"Zambianco, M., Cretti, S., Siracusa, D.: Cost minimization in multi-cloud systems with runtime microservice re-orchestration. In: Proc. of the 27th Conference on Innovation in Clouds, Internet and Networks, ICIN 2024, Paris, France, March 11-14, 2024, pp. 65\u201372 (2024). https:\/\/doi.org\/10.1109\/ICIN60470.2024.10494463","DOI":"10.1109\/ICIN60470.2024.10494463"},{"issue":"1","key":"9986_CR3","doi-asserted-by":"publisher","first-page":"135","DOI":"10.1186\/S13677-023-00516-5","volume":"12","author":"A Ullah","year":"2023","unstructured":"Ullah, A., Kiss, T., Kov\u00e1cs, J., Tusa, F., Deslauriers, J., Dagdeviren, H., Arjun, R., Hamzeh, H.: Orchestration in the cloud-to-things compute continuum: taxonomy, survey and future directions. J. Cloud Comput. 12(1), 135 (2023). https:\/\/doi.org\/10.1186\/S13677-023-00516-5","journal-title":"J. Cloud Comput."},{"issue":"Supplement","key":"9986_CR4","doi-asserted-by":"publisher","first-page":"6111","DOI":"10.1007\/S10586-018-1850-7","volume":"22","author":"F Cai","year":"2019","unstructured":"Cai, F., Zhu, N., He, J., Mu, P., Li, W., Yu, Y.: Survey of access control models and technologies for cloud computing. Clust. Comput. 22(Supplement), 6111\u20136122 (2019). https:\/\/doi.org\/10.1007\/S10586-018-1850-7","journal-title":"Clust. Comput."},{"issue":"2","key":"9986_CR5","doi-asserted-by":"publisher","first-page":"1497","DOI":"10.1007\/S10586-021-03517-8","volume":"25","author":"X Wang","year":"2022","unstructured":"Wang, X., Du, J., Liu, H.: Performance and isolation analysis of runc, gvisor and kata containers runtimes. Clust. Comput. 25(2), 1497\u20131513 (2022). https:\/\/doi.org\/10.1007\/S10586-021-03517-8","journal-title":"Clust. Comput."},{"key":"9986_CR6","unstructured":"Wiz: The 2023 Kubernetes Security Report. Available: https:\/\/www.wiz.io\/lp\/the-2023-kubernetes-security-report, Visited: 2025-02-28"},{"issue":"5","key":"9986_CR7","doi-asserted-by":"publisher","first-page":"46","DOI":"10.1109\/MSEC.2021.3094726","volume":"19","author":"F Minna","year":"2021","unstructured":"Minna, F., Blaise, A., Rebecchi, F., Chandrasekaran, B., Massacci, F.: Understanding the security implications of Kubernetes networking. IEEE Secur. Priv. 19(5), 46\u201356 (2021). https:\/\/doi.org\/10.1109\/MSEC.2021.3094726","journal-title":"IEEE Secur. Priv."},{"key":"9986_CR8","doi-asserted-by":"publisher","unstructured":"Budigiri, G., Baumann, C., M\u00fchlberg, J.T., Truyen, E., Joosen, W.: Network policies in kubernetes: Performance evaluation and security analysis. In: Joint European Conference on Networks and Communications & 6G Summit, EuCNC\/6G Summit 2021, Porto, Portugal, June 8-11, 2021, pp. 407\u2013412 (2021). https:\/\/doi.org\/10.1109\/EuCNC\/6GSummit51104.2021.9482526","DOI":"10.1109\/EuCNC\/6GSummit51104.2021.9482526"},{"key":"9986_CR9","doi-asserted-by":"publisher","unstructured":"Pizzato, F., Bringhenti, D., Sisto, R., Valenza, F.: An intent-based solution for network isolation in Kubernetes. In: 10th IEEE International Conference on Network Softwarization, NetSoft 2024, Saint Louis, MO, USA, June 24-28, 2024, pp. 381\u2013386 (2024). https:\/\/doi.org\/10.1109\/NetSoft60951.2024.10588939","DOI":"10.1109\/NetSoft60951.2024.10588939"},{"issue":"3","key":"9986_CR10","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1145\/3616401","volume":"56","author":"D Bringhenti","year":"2024","unstructured":"Bringhenti, D., Marchetto, G., Sisto, R., Valenza, F.: Automation for network security configuration: state of the art and research trends. ACM Comput. Surv. 56(3), 57\u201315737 (2024). https:\/\/doi.org\/10.1145\/3616401","journal-title":"ACM Comput. Surv."},{"key":"9986_CR11","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2023.109745","volume":"228","author":"D Bringhenti","year":"2023","unstructured":"Bringhenti, D., Sisto, R., Valenza, F.: A novel abstraction for security configuration in virtual networks. Comput. Netw. 228, 109745 (2023). https:\/\/doi.org\/10.1016\/j.comnet.2023.109745","journal-title":"Comput. Netw."},{"key":"9986_CR12","doi-asserted-by":"publisher","unstructured":"Scheid, E.J., Machado, C.C., Franco, M.F., Santos, R.L., Pfitscher, R.J., Filho, A.E.S., Granville, L.Z.: Inspire: Integrated nfv-based intent refinement environment. In: Proc. of the IFIP\/IEEE Symp. on Integrated Network and Service Management (IM17) (2017). https:\/\/doi.org\/10.23919\/INM.2017.7987279","DOI":"10.23919\/INM.2017.7987279"},{"key":"9986_CR13","doi-asserted-by":"publisher","unstructured":"Bringhenti, D., Marchetto, G., Sisto, R., Valenza, F., Yusupov, J.: Introducing programmability and automation in the synthesis of virtual firewall rules. In: Proc. of 6th IEEE Conference on Network Softwarization, NetSoft 2020, Ghent, Belgium, June 29\u2013July 3, 2020, pp. 473\u2013478 (2020). https:\/\/doi.org\/10.1109\/NetSoft48620.2020.9165434","DOI":"10.1109\/NetSoft48620.2020.9165434"},{"issue":"2","key":"9986_CR14","doi-asserted-by":"publisher","first-page":"1559","DOI":"10.1109\/TDSC.2022.3160293","volume":"20","author":"D Bringhenti","year":"2023","unstructured":"Bringhenti, D., Marchetto, G., Sisto, R., Valenza, F., Yusupov, J.: Automated firewall configuration in virtual networks. IEEE Trans. Depend. Secur. Comput. 20(2), 1559 (2023). https:\/\/doi.org\/10.1109\/TDSC.2022.3160293","journal-title":"IEEE Trans. Depend. Secur. Comput."},{"issue":"4","key":"9986_CR15","doi-asserted-by":"publisher","first-page":"289","DOI":"10.1364\/jocn.10.000289","volume":"10","author":"T Szyrkowiec","year":"2018","unstructured":"Szyrkowiec, T., Santuari, M., Chamania, M., Siracusa, D., Autenrieth, A., L\u00f3pez, V., Cho, J.Y., Kellerer, W.: Automatic intent-based secure service creation through a multilayer SDN network orchestration. J. Opt. Commun. Netw. 10(4), 289\u2013297 (2018). https:\/\/doi.org\/10.1364\/jocn.10.000289","journal-title":"J. Opt. Commun. Netw."},{"key":"9986_CR16","doi-asserted-by":"publisher","unstructured":"Cauli, C., Li, M., Piterman, N., Tkachuk, O.: Pre-deployment security assessment for cloud services through semantic reasoning. In: Proc. of Computer Aided Verification (CAV), Springer - 33rd International Conference, Virtual Event, July 20\u201323, 2021. Lecture Notes in Computer Science, vol. 12759, pp. 767\u2013780 (2021). https:\/\/doi.org\/10.1007\/978-3-030-81685-8_36","DOI":"10.1007\/978-3-030-81685-8_36"},{"key":"9986_CR17","doi-asserted-by":"publisher","unstructured":"Backes, J., Bolignano, P., Cook, B., Dodge, C., Gacek, A., Luckow, K.S., Rungta, N., Tkachuk, O., Varming, C.: Semantic-based automated reasoning for AWS access policies using SMT. In: 2018 Formal Methods in Computer Aided Design, FMCAD 2018, Austin, TX, USA, October 30 - November 2, 2018, pp. 1\u20139 (2018). https:\/\/doi.org\/10.23919\/FMCAD.2018.8602994","DOI":"10.23919\/FMCAD.2018.8602994"},{"key":"9986_CR18","doi-asserted-by":"publisher","unstructured":"Backes, J., Bayless, S., Cook, B., Dodge, C., Gacek, A., Hu, A.J., Kahsai, T., Kocik, B., Kotelnikov, E., Kukovec, J., McLaughlin, S., Reed, J., Rungta, N., Sizemore, J., Stalzer, M.A., Srinivasan, P., Subotic, P., Varming, C., Whaley, B.: Reachability analysis for aws-based networks. In: Computer Aided Verification - 31st International Conference, CAV 2019, New York City, NY, USA, July 15\u201318, 2019, Proceedings, Part II. Lecture Notes in Computer Science, vol. 11562, pp. 231\u2013241 (2019). https:\/\/doi.org\/10.1007\/978-3-030-25543-5_14","DOI":"10.1007\/978-3-030-25543-5_14"},{"key":"9986_CR19","doi-asserted-by":"publisher","unstructured":"Blaise, A., Rebecchi, F.: Stay at the helm: secure Kubernetes deployments via graph generation and attack reconstruction. In: IEEE 15th Int. Conf. on Cloud Computing, Barcelona, Spain, July 10\u201316, 2022, pp. 59\u201369 (2022). https:\/\/doi.org\/10.1109\/CLOUD55607.2022.00022","DOI":"10.1109\/CLOUD55607.2022.00022"},{"key":"9986_CR20","doi-asserted-by":"publisher","unstructured":"Minna, F., Massacci, F., Tuma, K.: Towards a security stress-test for cloud configurations. In: IEEE 15th Int. Conf. on Cloud Computing, Barcelona, Spain, July 10\u201316, 2022, pp. 191\u2013196 (2022). https:\/\/doi.org\/10.1109\/CLOUD55607.2022.00038","DOI":"10.1109\/CLOUD55607.2022.00038"},{"key":"9986_CR21","doi-asserted-by":"publisher","unstructured":"Zhu, H., Gehrmann, C.: Kub-Sec, an automatic Kubernetes cluster AppArmor profile generation engine. In: 14th International Conference on Communication Systems & Networks, COMSNETS 2022, Bangalore, India, Jan 4\u20138, 2022, pp. 129\u2013137 (2022). https:\/\/doi.org\/10.1109\/COMSNETS53615.2022.9668504","DOI":"10.1109\/COMSNETS53615.2022.9668504"},{"key":"9986_CR22","doi-asserted-by":"publisher","unstructured":"Haque, M.U., Kholoosi, M.M., Babar, M.A.: KGSecConfig: A knowledge graph based approach for secured container orchestrator configuration. In: IEEE International Conference on Software Analysis, Evolution and Reengineering, SANER 2022, Honolulu, HI, USA, March 15\u201318, 2022, pp. 420\u2013431 (2022). https:\/\/doi.org\/10.1109\/SANER53432.2022.00057","DOI":"10.1109\/SANER53432.2022.00057"},{"key":"9986_CR23","unstructured":"Li, X., Chen, Y., Lin, Z., Wang, X., Chen, J.H.: Automatic policy generation for inter-service access control of microservices. In: 30th USENIX Security Symposium, USENIX Security 2021, August 11\u201313, 2021, pp. 3971\u20133988 (2021). https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/li-xing"},{"key":"9986_CR24","unstructured":"EU Project: Flexible, scaLable and secUre decentralizeD Operating System (FLUIDOS). [Online]. Available: https:\/\/www.fluidos.eu\/ (2022\u20132025)"},{"key":"9986_CR25","unstructured":"EU Project: Towards a functional continuum operating system (ICOS). [Online]. Available: https:\/\/icos-project.eu\/ (2022\u20132025)"},{"key":"9986_CR26","unstructured":"EU Project: Autonomous, scalablE, tRusthworthy, intelligent European meta operating system for IoT edge-cloud continuum (aerOS). [Online]. Available: https:\/\/aeros-project.eu\/ (2022\u20132025)"},{"key":"9986_CR27","unstructured":"EU Project: A meta operating system for brokering hyper-distributes applications on cloud computing continuum (NebulOuS). [Online]. Available: https:\/\/nebulouscloud.eu\/ (2022\u20132025)"},{"key":"9986_CR28","unstructured":"EU Project: Next Generation Meta Operating Sytem (NEMO). [Online]. Available: https:\/\/meta-os.eu\/ (2022\u20132025)"},{"key":"9986_CR29","unstructured":"EU Project: A lightweight software stack and synergetic meta-orchestration framework for the next generation compute continuum (NEPHELE). [Online]. Available: https:\/\/nephele-project.eu\/ (2022\u20132025)"},{"key":"9986_CR30","doi-asserted-by":"publisher","unstructured":"Task Force 3: Architecture: Developing a Reference Architecture for the Continuum - Concept, Taxonomy and Building Blocks. Zenodo (2023). https:\/\/doi.org\/10.5281\/zenodo.8403593","DOI":"10.5281\/zenodo.8403593"},{"key":"9986_CR31","unstructured":"Liqo Available: https:\/\/liqo.io, Visited: 2024-03-27"},{"key":"9986_CR32","unstructured":"Documentation Available: https:\/\/kubernetes.io\/docs\/concepts\/services-networking\/network-policies\/, Visited: 2025-02-28"},{"key":"9986_CR33","unstructured":"Calico Available: https:\/\/tigera.io\/project-calico, Visited: 2025-02-28"},{"issue":"1","key":"9986_CR34","doi-asserted-by":"publisher","first-page":"45","DOI":"10.1109\/MSEC.2021.3117471","volume":"20","author":"D Bringhenti","year":"2022","unstructured":"Bringhenti, D., Valenza, F., Basile, C.: Toward cybersecurity personalization in smart homes. IEEE Secur. Priv. 20(1), 45\u201353 (2022). https:\/\/doi.org\/10.1109\/MSEC.2021.3117471","journal-title":"IEEE Secur. Priv."},{"issue":"13","key":"9986_CR35","doi-asserted-by":"publisher","first-page":"3622","DOI":"10.3390\/s20133622","volume":"20","author":"AM Zarca","year":"2020","unstructured":"Zarca, A.M., Bagaa, M., Bernab\u00e9, J.B., Taleb, T., Skarmeta, A.F.: Semantic-aware security orchestration in sdn\/nfv-enabled iot systems. Sensors 20(13), 3622 (2020). https:\/\/doi.org\/10.3390\/s20133622","journal-title":"Sensors"}],"container-title":["Journal of Network and Systems Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-025-09986-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10922-025-09986-1","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-025-09986-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T03:12:54Z","timestamp":1769915574000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10922-025-09986-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,17]]},"references-count":35,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,1]]}},"alternative-id":["9986"],"URL":"https:\/\/doi.org\/10.1007\/s10922-025-09986-1","relation":{},"ISSN":["1064-7570","1573-7705"],"issn-type":[{"value":"1064-7570","type":"print"},{"value":"1573-7705","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,17]]},"assertion":[{"value":"28 March 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"31 July 2025","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 September 2025","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 October 2025","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no Conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"6"}}