{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:27:35Z","timestamp":1784302055373,"version":"3.55.0"},"reference-count":149,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2023,10,5]],"date-time":"2023-10-05T00:00:00Z","timestamp":1696464000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2024,3,31]]},"abstract":"<jats:p>The size and complexity of modern computer networks are progressively increasing, as a consequence of novel architectural paradigms such as the Internet of Things and network virtualization. Consequently, a manual orchestration and configuration of network security functions is no more feasible in an environment where cyber attacks can dramatically exploit breaches related to any minimum configuration error. A new frontier is then the introduction of automation in network security configuration, i.e., automatically designing the architecture of security services and the configurations of network security functions, such as firewalls, Virtual Private Networks gateways, and so on. This opportunity has been enabled by modern computer networks technologies, such as virtualization. In view of these considerations, the motivations for the introduction of automation in network security configuration are first introduced, along with the key automation enablers. Then, the current state of the art in this context is surveyed, focusing on both the achieved improvements and the current limitations. Finally, possible future trends in the field are illustrated.<\/jats:p>","DOI":"10.1145\/3616401","type":"journal-article","created":{"date-parts":[[2023,8,17]],"date-time":"2023-08-17T12:05:46Z","timestamp":1692273946000},"page":"1-37","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":54,"title":["Automation for Network Security Configuration: State of the Art and Research Trends"],"prefix":"10.1145","volume":"56","author":[{"given":"Daniele","family":"Bringhenti","sequence":"first","affiliation":[{"name":"Dipartimento\u00a0di\u00a0Automatica e Informatica, Politecnico di Torino, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guido","family":"Marchetto","sequence":"additional","affiliation":[{"name":"Dipartimento\u00a0di\u00a0Automatica e Informatica, Politecnico di Torino, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Riccardo","family":"Sisto","sequence":"additional","affiliation":[{"name":"Dipartimento\u00a0di\u00a0Automatica e Informatica, Politecnico di Torino, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fulvio","family":"Valenza","sequence":"additional","affiliation":[{"name":"Dipartimento\u00a0di\u00a0Automatica e Informatica, Politecnico di Torino, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,10,5]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2012.2198666"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11277-019-06407-w"},{"key":"e_1_3_2_4_2","article-title":"A survey on various cyber attacks and their classification","volume":"15","author":"Uma M.","year":"2013","unstructured":"M. Uma and G. Padmavathi. 2013. A survey on various cyber attacks and their classification. Int J. Netw. Secur. 15 (5) (2013), 390\u2013396.","journal-title":"Int J. Netw. Secur."},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2020.3045781"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2015.2477041"},{"key":"e_1_3_2_7_2","volume-title":"IEEE SDN for Future Networks and Services (SDN4FNS\u201913)","author":"Scott-Hayward Sandra","year":"2013","unstructured":"Sandra Scott-Hayward, Gemma O\u2019Callaghan, and Sakir Sezer. 2013. SDN security: A survey. In IEEE SDN for Future Networks and Services (SDN4FNS\u201913). IEEE, Los Alamitos, CA."},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10922-007-9083-8"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2016.2598420"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2015.2463811"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3295749"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2005.854119"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2017.2708096"},{"key":"e_1_3_2_14_2","volume-title":"Proceedings of the 33rd International Convention on Information and Communication Technology, Electronics and Microelectronics (MIPRO\u201910)","author":"Popovic Kresimir","year":"2010","unstructured":"Kresimir Popovic and Zeljko Hocenski. 2010. Cloud computing security issues and challenges. In Proceedings of the 33rd International Convention on Information and Communication Technology, Electronics and Microelectronics (MIPRO\u201910)."},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2014.2327754"},{"key":"e_1_3_2_16_2","volume-title":"Proceedings of the Workshop on the Economics of Information Security","author":"Haislip Jacob Z.","year":"2019","unstructured":"Jacob Z. Haislip and Kalin S. Kolev. 2019. The economic cost of cybersecurity breaches: A broad-based analysis. In Proceedings of the Workshop on the Economics of Information Security."},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-94268-1_81"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-65610-2_17"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/TASE.2011.2178910"},{"key":"e_1_3_2_20_2","article-title":"Software-defined networking (SDN): Layers and architecture terminology","author":"Haleplidis Evangelos","year":"2015","unstructured":"Evangelos Haleplidis, Kostas Pentikousis, Spyros G. Denazis, Jamal Hadi Salim, David Meyer, and Odysseas G. Koufopavlou. 2015. Software-defined networking (SDN): Layers and architecture terminology. RFC 7426.","journal-title":"RFC 7426"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/1355734.1355746"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1145\/3287306"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10723-016-9366-y"},{"key":"e_1_3_2_24_2","article-title":"Policy core information model\u2014Version 1 specification","author":"Moore Bob","year":"2001","unstructured":"Bob Moore, Ed Ellesson, John Strassner, and Andrea Westerinen. 2001. Policy core information model\u2014Version 1 specification. RFC 3060.","journal-title":"RFC 3060"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.5555\/646962.712108"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2004.31"},{"key":"e_1_3_2_27_2","unstructured":"Lalana Kagal. 2002. Rei: A Policy Language for the Me-Centric Project. HP Labs."},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.5555\/1395083.1395690"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2008.04.018"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2019.2895278"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3010209"},{"key":"e_1_3_2_32_2","article-title":"The\u2019problem\u2019 with automation: Inappropriate feedback and interaction, not \u2018over-automation\u2019","author":"Norman Donald","year":"1990","unstructured":"Donald Norman. 1990. The\u2019problem\u2019 with automation: Inappropriate feedback and interaction, not \u2018over-automation\u2019. Philos. Trans. Roy. Soc. Lond. Ser. B Biol. Sci. 327, 1241 (1990), 585\u2013593.","journal-title":"Philos. Trans. Roy. Soc. Lond. Ser. B Biol. Sci."},{"key":"e_1_3_2_33_2","article-title":"Procedures for performing systematic reviews","volume":"33","author":"Kitchenham Barbara","year":"2004","unstructured":"Barbara Kitchenham. 2004. Procedures for performing systematic reviews. Keele, UK, Keele Univ. 33 (2004).","journal-title":"Keele, UK, Keele Univ."},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/1035582.1035583"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-11207-2"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.23919\/INM.2017.7987279"},{"issue":"2","key":"e_1_3_2_37_2","article-title":"Automated synthesis of distributed network access controls: A formal framework with refinement","volume":"28","author":"Rahman Mohammad Ashiqur","year":"2017","unstructured":"Mohammad Ashiqur Rahman and Ehab Al-Shaer. 2017. Automated synthesis of distributed network access controls: A formal framework with refinement. IEEE Trans. Parallel Distrib. Syst. 28, 2 (2017), 416\u2013430.","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"e_1_3_2_38_2","article-title":"Service function chaining (SFC) architecture","author":"Halpern Joel M.","year":"2015","unstructured":"Joel M. Halpern and Carlos Pignataro. 2015. Service function chaining (SFC) architecture. RFC 7665.","journal-title":"RFC 7665"},{"key":"e_1_3_2_39_2","article-title":"Problem statement for service function chaining","author":"Quinn Paul","year":"2015","unstructured":"Paul Quinn and Thomas D. Nadeau. 2015. Problem statement for service function chaining. RFC 7498.","journal-title":"RFC 7498"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2019.102419"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2821179"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICUFN.2016.7536925"},{"issue":"5","key":"e_1_3_2_43_2","article-title":"Enhancing IoT security through network softwarization and virtual security appliances","volume":"28","author":"Zarca Alejandro Molina","year":"2018","unstructured":"Alejandro Molina Zarca, Jorge Bernal Bernab\u00e9, Ivan Farris, Yacine Khettab, Tarik Taleb, and Antonio F. Skarmeta. 2018. Enhancing IoT security through network softwarization and virtual security appliances. Int. J. Netw. Manage. 28, 5 (2018), 1\u201318.","journal-title":"Int. J. Netw. Manage."},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2021.3117471"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1145\/2788397"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2012.05.003"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2016.10.015"},{"key":"e_1_3_2_48_2","volume-title":"Proceedings of the 20th Network and Distributed System Security Symposium","author":"Shin Seungwon","year":"2013","unstructured":"Seungwon Shin, Phillip A. Porras, Vinod Yegneswaran, Martin W. Fong, Guofei Gu, and Mabry Tyson. 2013. FRESCO: Modular composable security services for software-defined networks. In Proceedings of the 20th Network and Distributed System Security Symposium"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1145\/2034773.2034812"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/2486001.2486022"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1145\/2785989.2785999"},{"key":"e_1_3_2_52_2","article-title":"Rule-based synthesis of chains of security functions for software-defined networks","volume":"76","author":"Schnepf Nicolas","year":"2018","unstructured":"Nicolas Schnepf, Remi Badonnel, Abdelkader Lahmadi, and Stephan Merz. 2018. Rule-based synthesis of chains of security functions for software-defined networks. Electr. Commun. EASST 76 (2018).","journal-title":"Electr. Commun. EASST"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1364\/JOCN.10.000289"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/3229584.3229590"},{"key":"e_1_3_2_55_2","volume-title":"Proceedings of the IFIP\/IEEE Int. Symposium on Integrated Network Management (INM\u201919)","author":"Schnepf Nicolas","year":"2019","unstructured":"Nicolas Schnepf, Remi Badonnel, Abdelkader Lahmadi, and Stephan Merz. 2019. Automated factorization of security chains in software-defined networks. In Proceedings of the IFIP\/IEEE Int. Symposium on Integrated Network Management (INM\u201919)."},{"key":"e_1_3_2_56_2","volume-title":"IEEE Symposium on Computers and Communication (ISCC\u201916)","author":"Scheid Eder J.","year":"2016","unstructured":"Eder J. Scheid, Cristian Cleder Machado, Ricardo Luis dos Santos, Alberto E. Schaeffer Filho, and Lisandro Zambenedetti Granville. 2016. Policy-based dynamic service chaining in network functions virtualization. In IEEE Symposium on Computers and Communication (ISCC\u201916)."},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1145\/3207677.3277992"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2016.24"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1155\/2017\/9534754"},{"key":"e_1_3_2_60_2","article-title":"A dynamic composition mechanism of security service chaining oriented to SDN\/NFV-enabled networks","volume":"6","author":"Liu Yicen","year":"2018","unstructured":"Yicen Liu, Yu Lu, Wenxin Qiao, and Xingkai Chen. 2018. A dynamic composition mechanism of security service chaining oriented to SDN\/NFV-enabled networks. IEEE Access 6 (2018), 53918\u201353929.","journal-title":"IEEE Access"},{"issue":"4","key":"e_1_3_2_61_2","article-title":"Efficient provisioning of security service function chaining using network security defense patterns","volume":"12","author":"Sendi Alireza Shameli","year":"2019","unstructured":"Alireza Shameli Sendi, Yosr Jarraya, Makan Pourzandi, and Mohamed Cheriet. 2019. Efficient provisioning of security service function chaining using network security defense patterns. IEEE Trans. Serv. Comput. 12, 4 (2019), 534\u2013549.","journal-title":"IEEE Trans. Serv. Comput."},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60774-0_5"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1109\/NETSOFT.2015.7116152"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2944982"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1109\/NetSoft51509.2021.9492654"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2023.109745"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.3390\/info8020065"},{"key":"e_1_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.1145\/3040992.3041005"},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2009.172"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS47738.2020.9110402"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3160293"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1109\/NetSoft54395.2022.9844025"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/CCCS.2019.8888130"},{"issue":"5","key":"e_1_3_2_74_2","article-title":"Modular SDN programming with pyretic","volume":"38","author":"Reich Joshua","year":"2013","unstructured":"Joshua Reich, Christopher Monsanto, Nate Foster, Jennifer Rexford, and David Walker. 2013. Modular SDN programming with pyretic. ;login: USENIX Mag. 38, 5 (2013).","journal-title":";login: USENIX Mag."},{"key":"e_1_3_2_75_2","volume-title":"Proceedings of the 2nd IFIP TC1 WG1.7 Workshop on Formal Aspects in Security and Trust (FAST\u201904)","author":"Cuppens Fr\u00e9d\u00e9ric","year":"2004","unstructured":"Fr\u00e9d\u00e9ric Cuppens, Nora Cuppens-Boulahia, Thierry Sans, and Alexandre Mi\u00e8ge. 2004. A formal approach to specify and deploy a network security policy. In Proceedings of the 2nd IFIP TC1 WG1.7 Workshop on Formal Aspects in Security and Trust (FAST\u201904)."},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1997.601327"},{"key":"e_1_3_2_77_2","volume-title":"Proceedings of the NATO Consultation, Command and Control Interoperable Networks for Secure Communication Symposium","author":"Keromytis Angelos","year":"2003","unstructured":"Angelos Keromytis, Kostas Anagnostakis, Sotiris Ioannidis, Michael Greenwald, and Jonathan Smith. 2003. Managing access control in large scale heterogeneous networks. In Proceedings of the NATO Consultation, Command and Control Interoperable Networks for Secure Communication Symposium"},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1109\/SAINT.2005.28"},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-009-9147-0"},{"issue":"4","key":"e_1_3_2_80_2","article-title":"Policy based security analysis in enterprise networks: A formal approach","volume":"7","author":"Bera Padmalochan","year":"2010","unstructured":"Padmalochan Bera, Soumya Kanti Ghosh, and Pallab Dasgupta. 2010. Policy based security analysis in enterprise networks: A formal approach. IEEE Trans. Netw. Service Manage. 7, 4 (2010), 231\u2013243.","journal-title":"IEEE Trans. Netw. Service Manage."},{"key":"e_1_3_2_81_2","volume-title":"Proceedings of the 7th International Conference of B Users","author":"Stouls Nicolas","year":"2007","unstructured":"Nicolas Stouls and Marie-Laure Potet. 2007. Security policy enforcement through refinement process. In Proceedings of the 7th International Conference of B Users."},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.5555\/1688933.1688962"},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2014.32"},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","DOI":"10.5220\/0005946201970206"},{"key":"e_1_3_2_85_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-63390-9_14"},{"key":"e_1_3_2_86_2","volume-title":"Proceedings of the 15th USENIX Symposium on Networked Systems Design and Implementation (NSDI\u201918)","author":"El-Hassany Ahmed","year":"2018","unstructured":"Ahmed El-Hassany, Petar Tsankov, Laurent Vanbever, and Martin T. Vechev. 2018. NetComplete: Practical network-wide configuration synthesis with autocompletion. In Proceedings of the 15th USENIX Symposium on Networked Systems Design and Implementation (NSDI\u201918)."},{"key":"e_1_3_2_87_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.09.013"},{"key":"e_1_3_2_88_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPEC54980.2022.9750776"},{"key":"e_1_3_2_89_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102683"},{"key":"e_1_3_2_90_2","volume-title":"Proceedings of the USENIX Annual Technical Conference","author":"Jacobs Arthur Selle","year":"2021","unstructured":"Arthur Selle Jacobs, Ricardo J. Pfitscher, Rafael Hengen Ribeiro, Ronaldo A. Ferreira, Lisandro Zambenedetti Granville, Walter Willinger, and Sanjay G. Rao. 2021. Hey, Lumi! using natural language for intent-based network management. In Proceedings of the USENIX Annual Technical Conference."},{"key":"e_1_3_2_91_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-70881-8_5"},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS47738.2020.9110399"},{"key":"e_1_3_2_93_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.2974727"},{"key":"e_1_3_2_94_2","unstructured":"Mark J. McArdle Brent A. Johnston Philip D. R. Nathan and James Dool. Automatically configuring a computer firewall based on a network connections. U.S. Patent 7 284 267 Mar. 2001."},{"key":"e_1_3_2_95_2","doi-asserted-by":"publisher","DOI":"10.1109\/DISCEX.2001.932156"},{"key":"e_1_3_2_96_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2004.1281597"},{"key":"e_1_3_2_97_2","article-title":"Detection of network security component misconfiguration by rewriting and correlation","author":"Cuppens Fr\u00e9d\u00e9ric","year":"2006","unstructured":"Fr\u00e9d\u00e9ric Cuppens, Nora Cuppens-Boulahia, and Joaquin Garcia-Alfaro. 2006. Detection of network security component misconfiguration by rewriting and correlation. Conference on Security in Network Architectures and Security of Information Systems.","journal-title":"Conference on Security in Network Architectures and Security of Information Systems"},{"key":"e_1_3_2_98_2","doi-asserted-by":"publisher","DOI":"10.5555\/1688933.1689019"},{"key":"e_1_3_2_99_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-84882-828-5_9"},{"key":"e_1_3_2_100_2","volume-title":"Proceedings of the 11th IEEE International Conference on Computer and Information Technology (CIT\u201911)","author":"Youssef Nihel Ben","year":"2011","unstructured":"Nihel Ben Youssef and Adel Bouhoula. 2011. A fully automatic approach for fixing firewall misconfigurations. In Proceedings of the 11th IEEE International Conference on Computer and Information Technology (CIT\u201911)."},{"key":"e_1_3_2_101_2","doi-asserted-by":"publisher","DOI":"10.1145\/2240166.2240177"},{"key":"e_1_3_2_102_2","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132753"},{"key":"e_1_3_2_103_2","doi-asserted-by":"crossref","unstructured":"Kamel Adi Lamia Hamza and Liviu Pene. 2018. Automatic security policy enforcement in computer systems. Comput. Secur. 73 (2018) 156\u2013171.","DOI":"10.1016\/j.cose.2017.10.012"},{"key":"e_1_3_2_104_2","volume-title":"Proceedings of the IEEE International Conference on Network Protocols","author":"Shin Seungwon","year":"2012","unstructured":"Seungwon Shin and Guofei Gu. 2012. CloudWatcher: Network security monitoring using OpenFlow in dynamic cloud networks (or: How to provide security monitoring as a service in clouds?). In Proceedings of the IEEE International Conference on Network Protocols."},{"key":"e_1_3_2_105_2","doi-asserted-by":"publisher","DOI":"10.1145\/3338468.3356830"},{"key":"e_1_3_2_106_2","doi-asserted-by":"publisher","DOI":"10.1145\/2342441.2342451"},{"key":"e_1_3_2_107_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2016.2517407"},{"key":"e_1_3_2_108_2","doi-asserted-by":"publisher","DOI":"10.23919\/INM.2017.7987280"},{"key":"e_1_3_2_109_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2018.2871023"},{"key":"e_1_3_2_110_2","article-title":"Counteracting attacks from malicious end hosts in software defined networks","author":"Varadharajan V.","year":"2019","unstructured":"V. Varadharajan and U. Tupakula. 2019. Counteracting attacks from malicious end hosts in software defined networks. IEEE Trans. Netw. Service Manage. (2019), 160\u2013174.","journal-title":"IEEE Trans. Netw. Service Manage."},{"key":"e_1_3_2_111_2","doi-asserted-by":"publisher","DOI":"10.3390\/electronics8101136"},{"key":"e_1_3_2_112_2","doi-asserted-by":"publisher","DOI":"10.3990\/2.24"},{"key":"e_1_3_2_113_2","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS.2004.1317665"},{"key":"e_1_3_2_114_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-35674-7_28"},{"key":"e_1_3_2_115_2","doi-asserted-by":"publisher","DOI":"10.1007\/11562436_18"},{"key":"e_1_3_2_116_2","volume-title":"Proceedings of the 4th International Conference Collaborative Computing: Networking, Applications and Worksharing, (CollaborateCom\u201908)","author":"Sadeghi Mohammad Mehdi Gilanian","year":"2008","unstructured":"Mohammad Mehdi Gilanian Sadeghi, Borhanuddin Mohd Ali, Hossein Pedram, Mehdi Dehghan, and Masoud Sabaei. 2008. A new method for creating efficient security policies in virtual private network. In Proceedings of the 4th International Conference Collaborative Computing: Networking, Applications and Worksharing, (CollaborateCom\u201908)."},{"key":"e_1_3_2_117_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10922-010-9168-7"},{"key":"e_1_3_2_118_2","doi-asserted-by":"publisher","DOI":"10.1109\/AINA.2010.99"},{"key":"e_1_3_2_119_2","volume-title":"Proceedings of the International Conference on Emerging Ubiquitous Systems and Pervasive Networks","author":"Firdaouss Lotfi","year":"2021","unstructured":"Lotfi Firdaouss, Ayoub Bahnasse, Belkadi Manal, and Yazidi Ikrame. 2021. Automated VPN configuration using DevOps. In Proceedings of the International Conference on Emerging Ubiquitous Systems and Pervasive Networks."},{"key":"e_1_3_2_120_2","doi-asserted-by":"publisher","DOI":"10.1145\/3411505.3418439"},{"key":"e_1_3_2_121_2","doi-asserted-by":"publisher","DOI":"10.1109\/WiMOB.2014.6962166"},{"key":"e_1_3_2_122_2","article-title":"Security policy enforcement for networked smart objects","volume":"108","author":"Sicari Sabrina","year":"2016","unstructured":"Sabrina Sicari, Alessandra Rizzardi, Daniele Miorandi, Cinzia Cappiello, and Alberto Coen-Porisini. 2016. Security policy enforcement for networked smart objects. Comput. Net. 108 (2016), 133\u2013147.","journal-title":"Comput. Net."},{"key":"e_1_3_2_123_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.smhl.2017.06.001"},{"key":"e_1_3_2_124_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20936-9_28"},{"key":"e_1_3_2_125_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.is.2017.07.006"},{"key":"e_1_3_2_126_2","article-title":"Decentralizing privacy enforcement for Internet of Things smart objects","volume":"143","author":"Sagirlar Gokhan","year":"2018","unstructured":"Gokhan Sagirlar, Barbara Carminati, and Elena Ferrari. 2018. Decentralizing privacy enforcement for Internet of Things smart objects. Comput. Net. 143 (2018), 112\u2013125.","journal-title":"Comput. Net."},{"key":"e_1_3_2_127_2","doi-asserted-by":"publisher","DOI":"10.1002\/cpe.6934"},{"key":"e_1_3_2_128_2","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380234"},{"issue":"28","key":"e_1_3_2_129_2","article-title":"Automated configuration synthesis for resilient smart metering infrastructure","volume":"8","author":"Rahman Mohammad Ashiqur","year":"2021","unstructured":"Mohammad Ashiqur Rahman, Amarjit Datta, and Ehab Al-Shaer. 2021. Automated configuration synthesis for resilient smart metering infrastructure. EAI Endors. Trans. Secur. Saf. 8, 28 (2021), 1\u201314.","journal-title":"EAI Endors. Trans. Secur. Saf."},{"key":"e_1_3_2_130_2","article-title":"Automatic, verifiable and optimized policy-based security enforcement for SDN-aware IoT networks","volume":"213","author":"Bringhenti Daniele","year":"2022","unstructured":"Daniele Bringhenti, Jalolliddin Yusupov, Alejandro Molina Zarca, Fulvio Valenza, Riccardo Sisto, Jorge Bernal Bernab\u00e9, and Antonio F. Skarmeta. 2022. Automatic, verifiable and optimized policy-based security enforcement for SDN-aware IoT networks. Comput. Net. 213 (2022), 1\u201312.","journal-title":"Comput. Net."},{"key":"e_1_3_2_131_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510547.3517923"},{"key":"e_1_3_2_132_2","article-title":"Intent-driven secure system design: Methodology and implementation","volume":"124","author":"En Ooi Sian","year":"2023","unstructured":"Ooi Sian En, Razvan Beuran, Takayuki Kuroda, Takuya Kuwahara, Ryosuke Hotchi, Norihito Fujita, and Yasuo Tan. 2023. Intent-driven secure system design: Methodology and implementation. Comput. Secur. 124 (2023), 1\u201320.","journal-title":"Comput. Secur."},{"key":"e_1_3_2_133_2","doi-asserted-by":"publisher","DOI":"10.1109\/GIOTS.2017.8016285"},{"key":"e_1_3_2_134_2","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2020.2986621"},{"issue":"13","key":"e_1_3_2_135_2","article-title":"Semantic-aware security orchestration in SDN\/NFV-enabled IoT systems","volume":"20","author":"Zarca Alejandro Molina","year":"2020","unstructured":"Alejandro Molina Zarca, Miloud Bagaa, Jorge Bernal Bernab\u00e9, Tarik Taleb, and Antonio F. Skarmeta. 2020. Semantic-aware security orchestration in SDN\/NFV-enabled IoT systems. Sensors 20, 13 (2020), 1\u201324.","journal-title":"Sensors"},{"key":"e_1_3_2_136_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510547.3517920"},{"key":"e_1_3_2_137_2","article-title":"Rigorous automated network security management","volume":"4","author":"Guttman Joshua D.","year":"2005","unstructured":"Joshua D. Guttman and Amy L. Herzog. 2005. Rigorous automated network security management. Int. J. Inf. Secur. 4 (1) (2005), 29\u201348.","journal-title":"Int. J. Inf. Secur."},{"issue":"6","key":"e_1_3_2_138_2","article-title":"Automatic analysis of firewall and network intrusion detection system configurations","volume":"15","author":"Uribe Tom\u00e1s E.","year":"2007","unstructured":"Tom\u00e1s E. Uribe and Steven Cheung. 2007. Automatic analysis of firewall and network intrusion detection system configurations. J. Comp. Sec. 15, 6 (2007), 691\u2013715.","journal-title":"J. Comp. Sec."},{"key":"e_1_3_2_139_2","doi-asserted-by":"publisher","DOI":"10.1109\/NetSoft54395.2022.9844057"},{"key":"e_1_3_2_140_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICTC52510.2021.9620979"},{"key":"e_1_3_2_141_2","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2000.848455"},{"key":"e_1_3_2_142_2","doi-asserted-by":"publisher","DOI":"10.1109\/DISCEX.2003.1194883"},{"key":"e_1_3_2_143_2","doi-asserted-by":"publisher","DOI":"10.1145\/1282380.1282382"},{"key":"e_1_3_2_144_2","doi-asserted-by":"publisher","DOI":"10.1109\/SDN4FNS.2013.6702548"},{"key":"e_1_3_2_145_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2016.2553778"},{"key":"e_1_3_2_146_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2019.100129"},{"key":"e_1_3_2_147_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.istr.2012.10.002"},{"key":"e_1_3_2_148_2","volume-title":"Proceedings of the International Summit on IoT Infrastructures","author":"Rizzardi Alessandra","year":"2015","unstructured":"Alessandra Rizzardi, Daniele Miorandi, Sabrina Sicari, Cinzia Cappiello, and Alberto Coen-Porisini. 2015. Networked smart objects: Moving data processing closer to the source. In Proceedings of the International Summit on IoT Infrastructures."},{"key":"e_1_3_2_149_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10270-021-00898-7"},{"key":"e_1_3_2_150_2","doi-asserted-by":"publisher","DOI":"10.5555\/646130.679670"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3616401","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3616401","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:45:32Z","timestamp":1750178732000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3616401"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,5]]},"references-count":149,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2024,3,31]]}},"alternative-id":["10.1145\/3616401"],"URL":"https:\/\/doi.org\/10.1145\/3616401","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,10,5]]},"assertion":[{"value":"2021-01-14","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-08-06","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-10-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}