arXiv:2505.10732cs.CRcs.AI2025-05被引 9

用大模型自动检查Windows密码策略合规性,效率高于人工。

Automating Security Audit Using Large Language Model based Agent: An Exploration Experiment

  • 用GPT-4+Langchain构建自动化审计代理,执行密码策略检查。
  • 能准确识别密码策略违规,效率优于传统人工审计。
  • 适合安全团队、合规人员快速验证系统配置合规性。

在快速变化的数字环境中,企业持续面临保障系统安全的压力。安全审计通过确保政策到位、控制措施实施并识别漏洞,帮助缓解网络安全风险。然而,传统审计多为手动操作,耗时且成本高。本文探索利用大语言模型(LLM)作为自主代理,执行部分安全审计任务——以Windows操作系统密码策略合规性检查为例。通过使用GPT-4与Langchain开展探索性实验,该代理能够准确标记密码策略违规项,表现出较传统人工审计更高的效率。尽管在复杂动态环境中的操作一致性仍存局限,该框架为未来实现实时威胁监测与合规检查提供了可行路径。

原文摘要 · Abstract (English)

In the current rapidly changing digital environment, businesses are under constant stress to ensure that their systems are secured. Security audits help to maintain a strong security posture by ensuring that policies are in place, controls are implemented, gaps are identified for cybersecurity risks mitigation. However, audits are usually manual, requiring much time and costs. This paper looks at the possibility of developing a framework to leverage Large Language Models (LLMs) as an autonomous agent to execute part of the security audit, namely with the field audit. password policy compliance for Windows operating system. Through the conduct of an exploration experiment of using GPT-4 with Langchain, the agent executed the audit tasks by accurately flagging password policy violations and appeared to be more efficient than traditional manual audits. Despite its potential limitations in operational consistency in complex and dynamic environment, the framework suggests possibilities to extend further to real-time threat monitoring and compliance checks.

安全审计大模型应用自动化合规检查

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。