用大模型自动把老旧安全手册转成标准机器可读格式
From Legacy to Standard: LLM-Assisted Transformation of Cybersecurity Playbooks into CACAO Format
- 用提示工程+大模型批量转换非结构化安全手册
- 转换后流程结构保留率高,语法错误显著减少
- 适合需要自动化响应的安全部门和平台集成者
现有网络安全应急响应手册多为异构、非机器可读格式,限制了其在安全编排、自动化与响应平台间的自动化与互操作性。本文研究结合提示工程的大语言模型在将遗留应急响应手册自动转化为标准化、机器可读的 CACAO 格式方面的适用性。我们系统评估多种提示工程技术,并精心设计提示以最大化语法准确性和语义保真度,确保控制流完整。提出的模块化转换流程包含语法检查器以保证语法正确性,并具备迭代优化机制,逐步减少语法错误。我们在一个自定义数据集上评估该方法,该数据集包含多样化的遗留手册及其人工构建的 CACAO 参考版本。结果表明,该方法在准确率上显著优于基线模型,有效捕捉复杂工作流结构,大幅降低错误率,展现出在自动化网络安全手册转换任务中的实际部署潜力。
原文摘要 · Abstract (English)
Existing cybersecurity playbooks are often written in heterogeneous, non-machine-readable formats, which limits their automation and interoperability across Security Orchestration, Automation, and Response platforms. This paper explores the suitability of Large Language Models, combined with Prompt Engineering, to automatically translate legacy incident response playbooks into the standardized, machine-readable CACAO format. We systematically examine various Prompt Engineering techniques and carefully design prompts aimed at maximizing syntactic accuracy and semantic fidelity for control flow preservation. Our modular transformation pipeline integrates a syntax checker to ensure syntactic correctness and features an iterative refinement mechanism that progressively reduces syntactic errors. We evaluate the proposed approach on a custom-generated dataset comprising diverse legacy playbooks paired with manually created CACAO references. The results demonstrate that our method significantly improves the accuracy of playbook transformation over baseline models, effectively captures complex workflow structures, and substantially reduces errors. It highlights the potential for practical deployment in automated cybersecurity playbook transformation tasks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。