AUTOMATED COMPLIANCE CONTROL OF NETWORK DEVICE CONFIGURATIONS WITH CYBERSECURITY REQUIREMENTS

Authors

  • M. Sashnova National University of Kyiv-Mohyla Academy image/svg+xml Author
  • Y. Vozniuk National University of Kyiv-Mohyla Academy image/svg+xml Author
  • D. Cherkasov National University of Kyiv-Mohyla Academy image/svg+xml Author
  • P. Maslov National University of Kyiv-Mohyla Academy image/svg+xml Author

DOI:

https://doi.org/10.17721/2519-481X/2026/90-07

Keywords:

administration automation, security audit, access control lists, CIS Benchmark, NetDevOps, network segmentation, Zero Trust, network devices

Abstract

The growing number of connected devices, the increasing diversity and complexity of network topologies, and the constant evolution of cyber threats greatly complicate the administration of network equipment. Configuring dozens or hundreds of routers and switches manually is labor-intensive, costly, and associated with a high risk of cyber threats. Configuration errors themselves are the reason for the success of most cyberattacks. The aim of the study is to develop and practically test a system for the automated validation of network device configurations. Specifically, the system should automatically identify the physical network topology, verify the compliance of settings with industry security standards, and automatically remediate detected vulnerabilities.

The system was implemented in Python using the Netmiko and PyVis libraries. The LLDP protocol (IEEE 802.1AB) was used to obtain topology information. Configuration checks were performed in accordance with 10 CIS Benchmark rules for Cisco IOS. The system was tested on a virtual GNS3 testbed consisting of Cisco IOS routers classified into security zones (Access, Restricted, DMZ) with dynamic OSPF routing.

 

The audit module detected a number of vulnerable settings (in particular, enabled Telnet), as a result of which the initial security-standard compliance score was 85%. After the automated application of fixes and the generation of extended access control lists (ACLs), the score was raised to 100%. In addition, the system successfully blocked an unauthorized access attempt from the Restricted zone to the database server, which confirmed the correctness of the generated filtering policies.

The proposed solution significantly reduces the time required to conduct an audit, eliminates the influence of the subjective human factor, and ensures the consistent implementation of security measures. The results of the study confirm that NetDevOps principles work quite effectively in solving the tasks of ensuring the protection of real networks.

Author Biographies

References

1. Verizon (2025) Data Breach Investigations Report. Available at: https://www.verizon.com/business/resources/reports/dbir/

2. Center for Internet Security (no date) CIS Cisco IOS Benchmark. Available at: https://www.cisecurity.org/benchmark/cisco

3. Leivadeas, A. and Falkner, M. (2023) 'A survey on intent-based networking', IEEE Communications Surveys & Tutorials, 25(1), pp. 625–655. https://doi.org/10.1109/COMST.2022.3215919

4. Gharbaoui, M., Sciarrone, F., Fontana, M., Castoldi, P. and Martini, B. (2026) 'Assurance and conflict detection in intent-based networking: a comprehensive survey and insights on standards and open-source tools', IEEE Transactions on Network and Service Management, 23, pp. 1891–1912. https://doi.org/10.1109/TNSM.2026.3651896

5. Bajpai, M. (2025) 'Automating network device configuration and compliance enforcement', SSRN Electronic Journal. https://doi.org/10.2139/ssrn.5057509

6. Thati, S.R. (2025) 'AI-driven automation for network configuration and compliance: transforming enterprise security posture', World Journal of Advanced Research and Reviews, 26(2), pp. 1216–1223. https://doi.org/10.30574/wjarr.2025.26.2.1693

7. Ficzere, D. and Varga, P. (2025) 'AI-driven network configuration and operation', in NOMS 2025 IEEE Network Operations and Management Symposium. IEEE, pp. 1–4. https://doi.org/10.1109/NOMS57970.2025.11073726

8. Mushtaq, S., Mohsin, M. and Mushtaq, M. (2025) 'A systematic literature review on the implementation and challenges of zero trust architecture across domains', Sensors, 25(19), 6118. https://doi.org/10.3390/s25196118

9. Basta, N., Ikram, M., Kaafar, M.A. and Walker, A. (2022) 'Towards a zero-trust micro-segmentation network security strategy: an evaluation framework', in NOMS 2022 IEEE/IFIP Network Operations and Management Symposium. IEEE, pp. 1–7. https://doi.org/10.1109/NOMS54207.2022.9789888

10. Rescorla, E. and Ylonen, T. (2006) RFC 4253: The Secure Shell (SSH) Transport Layer Protocol. IETF. Available at: https://www.rfc-editor.org/rfc/rfc4253

11. PyVis (no date) PyVis documentation. Available at: https://pyvis.readthedocs.io/en/latest/

12. GNS3 (no date) GNS3 documentation. Available at: https://docs.gns3.com/

Published

2026-03-20

Issue

Section

INFORMATION TECHNOLOGIES