用生成式AI把安全策略编写时间从两天缩短到一分钟。
Enhancing Security Control Production With Generative AI
- 用大模型+上下文学习生成结构化Gherkin代码。
- 在AWS上实现从2-3天到不足1分钟的效率提升。
- 适合云安全团队快速构建合规性控制策略。
安全控制是用于降低风险、保护信息并确保云服务符合安全法规的机制或策略。传统上,安全控制的开发过程耗时且劳动密集。本文探索使用生成式AI加速安全控制的生成,特别聚焦于生成Gherkin代码——一种用于以结构化、可读方式定义安全控制行为的领域特定语言。通过利用大语言模型和上下文学习,我们提出一个结构化框架,将安全控制开发时间从2-3天缩短至不到一分钟。该方法结合详细任务描述、分步指令与检索增强生成,提升了生成代码的准确性和效率。在AWS云服务上的初步评估表明,生成式AI能有效简化安全控制开发流程,为云基础设施提供强大而动态的安全保障。
原文摘要 · Abstract (English)
Security controls are mechanisms or policies designed for cloud based services to reduce risk, protect information, and ensure compliance with security regulations. The development of security controls is traditionally a labor-intensive and time-consuming process. This paper explores the use of Generative AI to accelerate the generation of security controls. We specifically focus on generating Gherkin codes which are the domain-specific language used to define the behavior of security controls in a structured and understandable format. By leveraging large language models and in-context learning, we propose a structured framework that reduces the time required for developing security controls from 2-3 days to less than one minute. Our approach integrates detailed task descriptions, step-by-step instructions, and retrieval-augmented generation to enhance the accuracy and efficiency of the generated Gherkin code. Initial evaluations on AWS cloud services demonstrate promising results, indicating that GenAI can effectively streamline the security control development process, thus providing a robust and dynamic safeguard for cloud-based infrastructures.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。