An LLM-Driven Framework for Image-Based Mininet Topology Generation with Intelligent Security Response
In response to the increasing use of automated network operations and intelligent cybersecurity management, this study presents an interactive network management system that integrates large language models with an agent-based architecture. The system combines simulation deployment, anomaly monitoring, and human-in-the-loop decision workflows in a unified framework. It accepts network topology diagrams in various formats, uses an LLM to interpret nodes and links, and converts them into a corresponding Mininet simulation environment. To support dynamic task execution, the system includes an intelligent agent that invokes MCP-based tools and connects to Telegram as a remote interactive interface for queries, control actions, and decision feedback. For the security evaluation, we simulate multiple attack scenarios and incorporate a traffic monitoring mechanism. When the system detects abnormal behavior, the agent immediately notifies the administrator and assists in selecting appropriate countermeasures, such as blocking or ignoring the threat. Experimental results show that the system provides an end-to-end workflow, from topology interpretation to environment deployment, and from event detection to interactive response. These results demonstrate the feasibility and extensibility of the proposed design for intelligent network maintenance and cyber threat mitigation.
Paper
Full text
An LLM-Driven Framework for Image-Based Mininet Topology Generation with Intelligent Security Response
Semantic Scholar · Computer Science · 2026
Abstract
In response to the increasing use of automated network operations and intelligent cybersecurity management, this study presents an interactive network management system that integrates large language models with an agent-based architecture. The system combines simulation deployment, anomaly monitoring, and human-in-the-loop decision workflows in a unified framework. It accepts network topology diagrams in various formats, uses an LLM to interpret nodes and links, and converts them into a corresponding Mininet simulation environment. To support dynamic task execution, the system includes an intelligent agent that invokes MCP-based tools and connects to Telegram as a remote interactive interface for queries, control actions, and decision feedback. For the security evaluation, we simulate multiple attack scenarios and incorporate a traffic monitoring mechanism. When the system detects abnormal behavior, the agent immediately notifies the administrator and assists in selecting appropriate countermeasures, such as blocking or ignoring the threat. Experimental results show that the system provides an end-to-end workflow, from topology interpretation to environment deployment, and from event detection to interactive response. These results demonstrate the feasibility and extensibility of the proposed design for intelligent network maintenance and cyber threat mitigation.