Design and implementation of automated firewall policy management in enterprise telecommunication systems using infrastructure-as-code

Authors

  • G. Grynkevych State University of Information and Communication Technologies, Kyiv
  • V. Vasylenko State University of Information and Communication Technologies, Kyiv
  • D. Rudin Capital One, Plano, Texas, USA
  • D. Pliekhov Mercury Intermedia, Inc., Brentwood, TN, USA

DOI:

https://doi.org/10.31673/2412-9070.2026.049412

Abstract

The paper presents an approach to automating firewall policy management in enterprise telecommunication systems using Infrastructure-as-Code and Security-as-Code practices. The relevance of the study is driven by the increasing complexity of network infrastructures, the growing number of interconnected services, and the need to ensure a high level of cybersecurity while reducing operational costs. Traditional approaches to managing firewall access rules, which rely on manual configuration, are associated with a high probability of errors, slow deployment of changes, and limited process transparency, which negatively affects both security and operational efficiency.
The study analyzes existing approaches to network security automation, including policyascode practices, integration with change management systems, and pipeline-based request processing. A model of an automated firewall policy management system is proposed, which includes the use of a centralized configuration repository, automated validation of access requests, network path analysis, and generation of implementation plans.
Special attention is given to the integration with telecommunication infrastructure, including analysis of network zones, traffic flows, and service dependencies. The proposed approach ensures consistency of access policies, improves control over configuration changes, and reduces risks associated with misconfigurations. A modular system design is considered, enabling adaptability to evolving technological environments.
Additionally, the system incorporates a two-stage risk classification model for automated request evaluation and a priority-aware concurrent processing mechanism that ensures preemption of time-sensitive security operations.
The results demonstrate that automation significantly reduces manual effort, improves processing speed of access requests, and enhances service delivery quality. The approach also increases transparency and repeatability of changes while minimizing human-related errors.

Keywords: firewall policy automation, network security, infrastructure as code, security as code, telecommunication systems, access control, cybersecurity.

Downloads

Published

2026-09-09

Issue

Section

Articles