用AI助手帮普通人快速分析公共安全系统威胁
ThreatGPT: An Agentic AI Framework for Enhancing Public Safety through Threat Modeling
- 通过自然语言描述系统组件,一键调用STRIDE等框架生成威胁模型
- 基于少量示例学习,自动识别潜在攻击路径与防护措施
- 适合工程师、安全员和政策制定者快速提升安全分析能力
随着城市与社区智能化程度提升,交通控制中心、应急响应网络和公共交通等安全系统日趋复杂,面临的威胁风险也同步增加,可能直接影响人们的生命安全。为应对这一挑战,我们提出ThreatGPT——一个智能型人工智能助手,帮助工程师、安全人员或政策制定者理解并分析公共安全系统中的威胁。用户无需具备深厚网络安全知识,只需描述关注的系统组件(如登录系统、数据存储、通信网络),点击按钮即可选择STRIDE、MITRE ATT&CK、CVE报告、NIST或CISA等主流框架进行分析。ThreatGPT不仅提供威胁信息,更像一位经验丰富的合作伙伴:通过少样本学习,从示例中理解上下文,生成相关且智能的威胁模型,指出潜在漏洞、攻击方式及防御策略。无论是保护城市基础设施还是本地医疗系统,该工具均能根据用户需求灵活适配。它融合人工智能与人类判断,使安全分析更高效、更准确、更具信心。
原文摘要 · Abstract (English)
As our cities and communities become smarter, the systems that keep us safe, such as traffic control centers, emergency response networks, and public transportation, also become more complex. With this complexity comes a greater risk of security threats that can affect not just machines but real people's lives. To address this challenge, we present ThreatGPT, an agentic Artificial Intelligence (AI) assistant built to help people whether they are engineers, safety officers, or policy makers to understand and analyze threats in public safety systems. Instead of requiring deep cybersecurity expertise, it allows users to simply describe the components of a system they are concerned about, such as login systems, data storage, or communication networks. Then, with the click of a button, users can choose how they want the system to be analyzed by using popular frameworks such as STRIDE, MITRE ATT&CK, CVE reports, NIST, or CISA. ThreatGPT is unique because it does not just provide threat information, but rather it acts like a knowledgeable partner. Using few-shot learning, the AI learns from examples and generates relevant smart threat models. It can highlight what might go wrong, how attackers could take advantage, and what can be done to prevent harm. Whether securing a city's infrastructure or a local health service, this tool adapts to users' needs. In simple terms, ThreatGPT brings together AI and human judgment to make our public systems safer. It is designed not just to analyze threats, but to empower people to understand and act on them, faster, smarter, and with more confidence.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。