Submitted:
07 July 2026
Posted:
08 July 2026
You are already at the latest version
Abstract
Cilium is among the most widely deployed Container Network Interfaces (CNIs), serving as the default CNI in Google Kubernetes Engine. It extends standard Kubernetes NetworkPolicy (KNP) with two additional types—CiliumNetworkPolicy (CNP) and CiliumClusterwideNetworkPolicy (CCNP)—each with distinct semantics. When all three coexist in a cluster, the resulting composition is difficult to reason about formally, leading to misconfiguration and security incidents. Existing verification tools, KANO and VeriKube, address subsets of the problem but share two critical limitations: neither provides a formal denotational semantics that precisely characterizes the three-layer composition, nor a canonical representation enabling policy-equivalence checking with completeness guarantees. We close this gap with three contributions. First, we develop the first formal denotational semantics for Cilium’s three-layer composed policy—KNP (additive), CNP (deny-wins), CCNP (cluster-override)—and prove that the composite function is Hyper-Rectangular Piecewise-Constant (HRPC-like). Second, we construct a canonical Reduced Ordered Interval Decision Diagram (ROIDD) for the composite policy space and prove a canonicity theorem, enabling policy-equivalence checking as structural isomorphism in O(|ROIDD|) time. Third, we develop certified conflict-detection algorithms for shadow, redundancy, and cross-layer conflict anomalies across all three layers with formal proofs of soundness and completeness. Experimental evaluation on synthetic policies confirms zero mismatches between ROIDD evaluation and ground-truth brute-force, ROIDD compression ratios of 5–15× over the unshared decision tree, and low-microsecond (0.56–1.52 µs) per-packet lookup latency regardless of policy size. A native C++ implementation, evaluated on the same policy dataset, reconstructs the identical decision-diagram structure and classifies each packet in under 45 ns—about 30× faster than the Python reference—confirming that sub-microsecond classification is inherent to the algorithm rather than an artifact of the implementation language.
Keywords:
1. Introduction
2. Background and Related Work
2.1. Cilium Policy Types
2.2. Related Work
3. Formal Semantics of Three-Layer Cilium Policy
3.1. Packet Space and Action Set
3.2. Single-Layer Semantics
3.3. Composition Semantics
3.4. Composite Policy Is HRPC-like
4. ROIDD for Cilium Policy
4.1. Ordered Interval Decision Diagrams
4.2. Construction Algorithm
| Algorithm 1 (ROIDD Construction). |
|
Input: Π = (KNP, CNP, CCNP), field order π. Output: ROIDD(Π, π). Phase 1 — Collect breakpoints: For each field Fj, collect all interval endpoints from all rules across all layers, forming the breakpoint set Bj. Phase 2 — Build per-layer OIDDs: For each layer L, build OIDDL by Shannon decomposition along π. At depth k, partition D(Fπ(k)) at Bπ(k) breakpoints; create one child per maximal constant interval; recurse. At depth 7 (all fields tested), label the node as a terminal with ⟦L⟧(p) for any representative p. Phase 3 — Compose: Merge OIDD_KNP, OIDD_CNP, OIDD_CCNP using the apply operation from Definition 7. At each leaf triple (aK, aC, aCC), output compose(…) ∈ A. Phase 4 — Reduce: Apply R1 and R2 exhaustively bottom-up using hash-cons to identify and merge isomorphic nodes. Complexity: O(|G|·|F|) for Phase 2, where |G| = ∏j (|Bj|+1) ≤ (2·|rules|+1)^7 in the worst case (exponential in |F| = 7, though bounded in practice by the actual breakpoint counts). Phase 3 (apply) is O(|OIDD_KNP|·|OIDD_CNP|·|OIDD_CCNP|) via a synchronized traversal of the three per-layer diagrams. Phase 4 is O(|ROIDD| log |ROIDD|) using hash-cons for node dedup. |
4.3. Canonicity and Equivalence Oracle
5. Conflict Detection Algorithms
| Algorithm 2 (Shadow Detection). |
|
Input: Π, ROIDD(Π, π). Output: Set of shadowed rules. 1: Compute H(r) the hyper-rectangle of packets matched by r. 2: Traverse the ROIDD restricting at each node v to I(e) ∩ H(r)[F(v)]. Collect all reachable terminal nodes. 3: If no terminal exists where r determines the composite action, output r as shadowed. Complexity: O(|ROIDD|·|rules|); faster in practice due to early pruning on empty intersections. |
| Algorithm 3 (Redundancy Detection). |
|
Input: Π, ROIDD(Π, π). Output: Set of redundant rules. 1: For each rule r ∈ L, build Πʹ = Π with r removed (incremental delta update on H(r)). 2: Build ROIDD(Πʹ, π). 3: If ROIDD(Π, π) ≅ ROIDD(Πʹ, π), output r as redundant. Complexity: O(|rules|) ROIDD rebuilds, each O(|G|·|F| + |ROIDD| log |ROIDD|) in the worst case (Algorithm 1), for a total of O(|rules|·|G|·|F|). A certified incremental DD-update scheme—recomputing only the subdiagram touched by H(r) rather than rebuilding from scratch—could reduce this to O(|ROIDD|) amortized per rule; we report the worst-case rebuild cost here and leave a certified incremental construction to future work. |
| Algorithm 4 (Cross-Layer Conflict & Unreachable Region Detection). |
|
Input: Π, ROIDD(Π, π). Output: Conflict pairs; unreachable hyper-rectangles. Cross-layer conflicts: for each pair (r ∈ L1, rʹ ∈ L2) with L1≠ L2: (1) Compute H(r) ∩ H(rʹ). If empty, skip. (2) If action(r) ≠ action(rʹ), record (r, rʹ) as a cross-layer conflict. Unreachable regions: for each terminal node t labelled deny in the ROIDD: (1) Reconstruct H(t) from the root-to-t path. (2) Check whether any rule in any layer explicitly denies H(t). (3) If none, record H(t) as an unreachable region. Complexity: O(|rules|2) cross-layer; O(|ROIDD|·|rules|) unreachable regions. |
6. Evaluation
6.1. Experimental Setup
6.2. Experiment 1: Correctness Validation
6.3. Experiment 2: Scalability
6.4. Experiment 3: Conflict Detection Accuracy
6.5. Experiment 4: Equivalence Oracle
6.6. Experiment 5: Field-Order Sensitivity
6.7. Threats to Validity
6.8. Native Implementation and Language Comparison
7. Discussion
7.1. Practical Deployment
7.2. Extension to L7 and Multi-Cluster
7.3. Generalization to Other CNIs
8. Conclusion
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
References
- Cilium Project. Cilium’s CIDR Deny Policies May Not Take Effect When a More Narrow CIDR Allow Is Present. Available online: https://github.com/cilium/cilium/security/advisories/GHSA-3wwx-63fv-pfq6 (accessed on October 2024).
- Datadog Engineering. Why CiliumNetworkPolicy Rules Block Traffic in Kubernetes Clusters. Available online: https://www.datadoghq.com/blog/cilium-network-policy-misconfigurations/ (accessed on December 2025).
- Li, Y.; Jia, C.; Hu, X.; Li, J. Kano: Efficient container network policy verification. In Proceedings of the 2020 IEEE Symposium on High-Performance Interconnects (HOTI), Santa Clara, CA, USA, August 2020; pp. 63–70. [CrossRef]
- Kang, H.; Shin, S. VeriKube: Automatic and efficient verification for container network policies. IEICE Trans. Inf. Syst. 2022, E105-D, 2131–2134. [CrossRef]
- Kulik, T.; Boudjadar, J. Cilium and VDM—Towards formal analysis of Cilium policies. arXiv 2024, arXiv:2410.12009.
- Cilium Project. Deny Policies. Cilium Documentation, Version 1.19. Available online: https://docs.cilium.io/en/stable/security/policy/deny/ (accessed on June 2026).
- Cilium Project. Network Policy. Cilium Documentation, Version 1.19. Available online: https://docs.cilium.io/en/stable/network/kubernetes/policy/ (accessed on June 2026).
- Cilium Project. Policy Enforcement Modes. Cilium Documentation, Version 1.19. Available online: https://docs.cilium.io/en/stable/security/policy/intro/ (accessed on June 2026).
- Gouda, M.G.; Liu, A.X. Structured firewall design. Comput. Netw. 2007, 51, 1106–1120. [CrossRef]
- Gouda, M.G.; Liu, A.X. Diverse firewall design. IEEE Trans. Parallel Distrib. Syst. 2008, 19, 1237–1251. [CrossRef]
- Al-Shaer, E.; Hamed, H. Discovery of policy anomalies in distributed firewalls. In Proceedings of the IEEE INFOCOM 2004, Hong Kong, China, March 2004; Volume 4, pp. 2605–2616. [CrossRef]
- Yu, M.; Li, F.; Yu, N.; Wang, X.; Guo, Y. Detecting conflict of heterogeneous access control policies. Digit. Commun. Netw. 2022, 8, 664–679. [CrossRef]
- Chomsiri, T.; He, X.; Nanda, P.; Tan, Z. Hybrid Tree-Rule Firewall for high speed data transmission. IEEE Trans. Cloud Comput. 2020, 8, 1237–1249. [CrossRef]
- Chomsiri, T.; He, X.; Nanda, P. Limitation of listed-rule firewall and the design of Tree-Rule Firewall. In Internet and Distributed Computing Systems, Proceedings of the 5th International Conference on Internet and Distributed Computing Systems (IDCS 2012), Wuyishan, China, 21–23 November 2012; Xiang, Y., Pathan, M., Tao, X., Wang, H., Eds.; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 2012; Volume 7646, pp. 275–287. [CrossRef]
- He, X.; Chomsiri, T.; Nanda, P.; Tan, Z. Improving cloud network security using the Tree-Rule firewall. Future Gener. Comput. Syst. 2014, 30, 116–126. [CrossRef]
- Booth, R.; Noisanguan, W. An axiomatic approach to firewall rule update. In Proceedings of the 6th International Joint Conference on Computer Science and Software Engineering (JCSSE 2009), Phuket, Thailand, May 2009.
- Booth, R.; Chandler, J. On strengthening the logic of iterated belief revision: Proper ordinal interval operators. Artif. Intell. 2020, 285, 103289. [CrossRef]
- Bryant, R.E. Graph-based algorithms for Boolean function manipulation. IEEE Trans. Comput. 1986, C-35, 677–691. [CrossRef]
| Work | Cilium multi-layer | Formal semantics |
Canonical form | Conflict +proof |
Equiv. oracle |
|---|---|---|---|---|---|
| KANO [3] | KNP only | No | Bit-matrix | No | No |
| VeriKube [4] | Partial | No | Novel graph | No | No |
| VDM-SL [5] | CNP only | Partial | No | No | No |
| FDD [9] | LR only | Yes | Yes | Yes | Yes |
| This work | All three | Yes (Thm. 1) | Yes (ROIDD) | Yes | Yes |
| Anomaly | Layer scope | Algorithm | Theorem |
|---|---|---|---|
| Shadow | Single- or cross-layer | Algorithm 2 | Theorem 4 |
| Redundancy | Single-layer | Algorithm 3 | Theorem 5 |
| Cross-layer conflict | Cross-layer | Algorithm 4 | Theorem 6 |
| Unreachable region | Composite (all layers) | Algorithm 4 | Theorem 6 |
| Config | Rules | ROIDD nodes | Tree nodes | Sharing ratio | Build (ms) | Mismatches |
|---|---|---|---|---|---|---|
| tiny | 5 | 27 | 103 | 3.81× | 70 | 0 |
| small | 9 | 62 | 515 | 8.31× | 128 | 0 |
| medium | 12 | 82 | 805 | 9.82× | 322 | 0 |
| large | 17 | 110 | 1313 | 11.94× | 372 | 0 |
| xlarge | 22 | 172 | 1903 | 11.06× | 423 | 0 |
| Total rules | ROIDD nodes | Tree nodes | Ratio | Build (ms) | Lookup (µs) |
|---|---|---|---|---|---|
| 4 | 28 | 143 | 5.11× | 64 | 0.56 |
| 8 | 58 | 416 | 7.17× | 71 | 0.82 |
| 12 | 78 | 943 | 12.09× | 203 | 0.86 |
| 17 | 128 | 1886 | 14.73× | 407 | 1.06 |
| 22 | 140 | 1748 | 12.49× | 548 | 1.13 |
| 27 | 174 | 2003 | 11.51× | 624 | 1.09 |
| 32 | 163 | 2227 | 13.66× | 754 | 1.14 |
| 38 | 366 | 5636 | 15.40× | 848 | 1.52 |
| Trial | Shadow (base→total, Δ) | Redundant (base→total, Δ) | Conflicts | Unreachable | Time (ms) |
|---|---|---|---|---|---|
| 1 | 2→7 (Δ5) | 1→6 (Δ5) | 3 | 271 | 6036 |
| 2 | 3→7 (Δ4) | 2→6 (Δ4) | 11 | 305 | 3534 |
| 3 | 1→8 (Δ7) | 0→7 (Δ7) | 11 | 472 | 4498 |
| 4 | 1→11 (Δ10) | 0→11 (Δ11) | 21 | 58 | 3746 |
| 5 | 4→8 (Δ4) | 3→6 (Δ3) | 5 | 316 | 2058 |
| Trial | same_iso | Time (µs) | diff_iso | Time (µs) | correct_same | correct_diff |
|---|---|---|---|---|---|---|
| 1 | True | 372.1 | False | 1.9 | True | True |
| 2 | True | 370.2 | False | 5.1 | True | True |
| 3 | True | 380.6 | False | 2.1 | True | True |
| 4 | True | 384.5 | False | 4.3 | True | True |
| 5 | True | 761.2 | False | 1.8 | True | True |
| Field order | ROIDD nodes | Tree nodes | Ratio | Build (ms) | Mismatches |
|---|---|---|---|---|---|
| slabel_first (default) | 161 | 3483 | 21.63× | 498 | 0 |
| dport_first | 173 | 2556 | 14.77× | 501 | 0 |
| ip_first | 128 | 1250 | 9.77× | 499 | 0 |
| label_dport_first | 136 | 2426 | 17.84× | 500 | 0 |
| reversed | 115 | 898 | 7.81× | 495 | 0 |
| Config | Rules | Nodes | Build Py (ms) | Build C++ (ms) | Lookup Py (ns) | Lookup C++ (ns) |
Speedup |
|---|---|---|---|---|---|---|---|
| tiny | 5 | 27 | 70.4 | 3.2 | 579.6 | 16.5 | 35× |
| small | 9 | 62 | 128.1 | 4.0 | 681.7 | 23.0 | 30× |
| medium | 12 | 82 | 322.5 | 8.9 | 813.7 | 28.8 | 28× |
| large | 17 | 110 | 372.4 | 7.7 | 889.2 | 31.5 | 28× |
| xlarge | 22 | 172 | 423.3 | 8.5 | 944.5 | 34.3 | 28× |
| scale-4 | 4 | 28 | 64.5 | 3.1 | 554.1 | 15.9 | 35× |
| scale-8 | 8 | 58 | 70.8 | 2.4 | 776.9 | 24.6 | 32× |
| scale-12 | 12 | 78 | 203.0 | 5.7 | 816.7 | 27.3 | 30× |
| scale-17 | 17 | 128 | 407.3 | 9.3 | 951.1 | 33.4 | 28× |
| scale-22 | 22 | 140 | 548.3 | 11.3 | 945.0 | 35.6 | 27× |
| scale-27 | 27 | 174 | 623.5 | 11.4 | 923.3 | 34.0 | 27× |
| scale-32 | 32 | 163 | 754.0 | 14.4 | 953.4 | 33.8 | 28× |
| scale-38 | 38 | 366 | 847.5 | 13.0 | 1130.1 | 43.4 | 26× |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).