arXiv:2509.10482cs.CRcs.AI2025-09

用生成式AI自动完成威胁建模,让小公司也能轻松做安全防护。

AegisShield: Democratizing Cyber Threat Modeling with Generative AI

  • 结合STRIDE和MITRE ATT&CK,用AI自动生成威胁并整合实时漏洞情报。
  • 在15个案例中减少威胁建模复杂度,85.4%的威胁能准确映射到攻击技术。
  • 适合资源有限的组织快速启动安全设计,推动安全默认实践落地。

技术系统日益复杂,传统威胁建模难以规模化,尤其对资源有限的小型组织。本文提出并评估了AegisShield——一个基于生成式AI的威胁建模工具,融合STRIDE与MITRE ATT&CK框架,实现威胁自动生成与系统化评估。通过集成国家漏洞数据库(NVD)与AlienVault开放威胁交换(OTX)的实时威胁情报,AegisShield生成简洁可读的威胁描述。对15个案例研究中的243个威胁及超过8000个AI生成威胁的评估显示:该工具显著降低建模复杂度(p < 0.001),生成内容与专家定义威胁语义一致(p < 0.05),85.4%的威胁可准确映射至MITRE ATT&CK攻击技术(p < 0.001)。自动化与标准化的威胁建模使资源匮乏组织能更早识别风险,助力安全优先设计的广泛采纳。

原文摘要 · Abstract (English)

The increasing sophistication of technology systems makes traditional threat modeling hard to scale, especially for small organizations with limited resources. This paper develops and evaluates AegisShield, a generative AI enhanced threat modeling tool that implements STRIDE and MITRE ATT&CK to automate threat generation and provide systematic assessments. By integrating real time threat intelligence from the National Vulnerability Database and AlienVault Open Threat Exchange, AegisShield produces streamlined and accessible threat descriptions. Our assessment of 243 threats from 15 case studies and over 8000 AI generated threats shows that AegisShield reduces complexity (p less than 0.001), yields outputs semantically aligned with expert developed threats (p less than 0.05), and achieves an 85.4 percent success rate in mapping threats to MITRE ATT&CK techniques (p less than 0.001). Automating and standardizing threat modeling helps under resourced organizations address risk earlier and supports wider adoption of secure by design practices.

威胁建模生成式AI安全防护MITRE ATT&CK

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。