用AI规划推理攻击图,帮管理员系统评估防御方案
SPEAR: Security Posture Evaluation using AI Planner-Reasoning on Attack-Connectivity Hypergraphs
- 用AI规划建模网络漏洞与配置,生成可解释的防御策略
- 自动生成多种硬化的可行方案,支持对比评估
- 适合安全管理员做假设分析,提升决策效率
现有基于图的网络安全框架在整合网络连接参数、不完全信息下的推理、可理解的建议输出以及支持“若-则”场景分析方面仍存在不足。本文提出SPEAR,一种结合人工智能规划推理的正式安全态势评估框架,支持人机协同。SPEAR采用AI规划中的因果形式,将网络配置与漏洞描述自动转化为规划模型(以PDDL表示)。该框架能识别出一组多样化的安全加固策略,并以领域专家可理解的方式呈现,使管理员能够系统探索加固方案空间,评估各方案的影响并进行对比。其核心优势在于实现自动化与可解释性的平衡,支持不同攻击动机和场景的假设分析。
原文摘要 · Abstract (English)
Graph-based frameworks are often used in network hardening to help a cyber defender understand how a network can be attacked and how the best defenses can be deployed. However, incorporating network connectivity parameters in the attack graph, reasoning about the attack graph when we do not have access to complete information, providing system administrator suggestions in an understandable format, and allowing them to do what-if analysis on various scenarios and attacker motives is still missing. We fill this gap by presenting SPEAR, a formal framework with tool support for security posture evaluation and analysis that keeps human-in-the-loop. SPEAR uses the causal formalism of AI planning to model vulnerabilities and configurations in a networked system. It automatically converts network configurations and vulnerability descriptions into planning models expressed in the Planning Domain Definition Language (PDDL). SPEAR identifies a set of diverse security hardening strategies that can be presented in a manner understandable to the domain expert. These allow the administrator to explore the network hardening solution space in a systematic fashion and help evaluate the impact and compare the different solutions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。