arXiv:2507.13076cs.CL2025-07被引 1

提出攻击场景的形式化模型,助力自动化攻防演练与分析。

Formalizing Attack Scenario Description: A Proposed Model

  • 用UML类图抽象攻击上下文与场景描述
  • 支持攻击脚本自动生成与分析流程上游输入
  • 适合安全自动化、红蓝对抗训练场景

组织面临不断变化的威胁环境,必须持续投入大量资源保护资产,推动网络安全自动化成为必然趋势。然而,流程自动化依赖输入数据的正式化表达。本文针对以攻击场景为输入的流程,提出一种新型形式化模型,涵盖攻击上下文与场景描述,采用UML类图进行抽象。模型构建完成后,展示了其在上游攻击分析流程中的应用,并验证了其在网络安全培训中自动生成攻击脚本的能力。这两项应用构成本文的第二项贡献。

原文摘要 · Abstract (English)

Organizations face an ever-changing threat landscape. They must continuously dedicate significant efforts to protect their assets, making their adoption of increased cybersecurity automation inevitable. However, process automation requires formalization of input data. Through this paper, we address this need for processes that use attack scenarios as input. Among these processes, one can mention both the generation of scripts for attack simulation and training purposes, as well as the analysis of attacks. Therefore, the paper's main research contribution is a novel formal model that encompasses the attack's context description and its scenario. It is abstracted using UML class model. Once the description of our model done, we will show how it could serve an upstream attack analysis process. We will show also its use for an automatic generation of attack scripts in the context of cybersecurity training. These two uses cases constitute the second contribution of this present research work.

攻击建模自动化安全UML

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。