arXiv:2506.00831cs.CRcs.AI2025-06被引 8

用大模型自动识别交通物联网系统威胁,降低安全专家依赖。

A Large Language Model-Supported Threat Modeling Framework for Transportation Cyber-Physical Systems

  • 基于大模型的三类方法,自动识别攻击路径与防御措施。
  • 73%攻击技术被专家验证正确,真实案例中成功预测勒索软件攻击链。
  • 适合缺乏安全专家的交通系统单位快速开展威胁建模。

针对交通网络中网络安全威胁建模框架范围窄、耗时且依赖专家的问题,本文提出面向交通信息物理系统的威胁建模框架(TraCR-TMF),该框架基于大语言模型(LLM),显著减少对安全专家的依赖。该框架通过三种基于LLM的方法实现威胁识别:(i) 无需专家干预的检索增强生成;(ii) 低干预的上下文学习;(iii) 中等干预的监督微调。框架可识别关键资产的攻击路径,结合已知漏洞的通用漏洞评分系统(CVSS)得分进行优先级排序。在两个案例中评估:其一,针对多种交通应用识别攻击技术,73%被专家验证为正确;其二,在真实网络攻击事件中成功预测了横向移动、数据窃取及勒索加密等行为。结果表明,该框架有效支持交通信息物理系统威胁建模,大幅降低专家介入需求。相关代码已开源,便于实际部署。

原文摘要 · Abstract (English)

Existing threat modeling frameworks related to transportation cyber-physical systems (CPS) are often narrow in scope, labor-intensive, and require substantial cybersecurity expertise. To this end, we introduce the Transportation Cybersecurity and Resiliency Threat Modeling Framework (TraCR-TMF), a large language model (LLM)-based threat modeling framework for transportation CPS that requires limited cybersecurity expert intervention. TraCR-TMF identifies threats, potential attack techniques, and relevant countermeasures for transportation CPS. Three LLM-based approaches support these identifications: (i) a retrieval-augmented generation approach requiring no cybersecurity expert intervention, (ii) an in-context learning approach with low expert intervention, and (iii) a supervised fine-tuning approach with moderate expert intervention. TraCR-TMF offers LLM-based attack path identification for critical assets based on vulnerabilities across transportation CPS entities. Additionally, it incorporates the Common Vulnerability Scoring System (CVSS) scores of known exploited vulnerabilities to prioritize threat mitigations. The framework was evaluated through two cases. First, the framework identified relevant attack techniques for various transportation CPS applications, 73% of which were validated by cybersecurity experts as correct. Second, the framework was used to identify attack paths for a target asset in a real-world cyberattack incident. TraCR-TMF successfully predicted exploitations, like lateral movement of adversaries, data exfiltration, and data encryption for ransomware, as reported in the incident. These findings show the efficacy of TraCR-TMF in transportation CPS threat modeling, while reducing the need for extensive involvement of cybersecurity experts. To facilitate real-world adoptions, all our codes are shared via an open-source repository.

威胁建模大模型交通系统安全自动化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。