用本地大模型辅助林区工控系统安全风险评估,兼顾隐私与效率。
Leveraging Large Language Models for Cybersecurity Risk Assessment -- A Case from Forestry Cyber-Physical Systems
- 基于检索增强的本地大模型生成初始风险评估
- 专家访谈与实测表明可提升评估效率并减少误判
- 适合需合规且缺安全专家的工业系统团队使用
在安全关键型软件系统中,网络安全活动至关重要,风险评估尤为关键。许多软件团队缺乏专职网络安全专家,导致现有专家负担过重,工程师不得不自行开展安全工作。为此,亟需一种工具支持专家与工程师在风险评估中识别漏洞与威胁。本文探索了在不外传数据的前提下,利用本地部署的大语言模型(LLM)结合检索增强生成技术,支持林业领域工控系统的网络安全风险评估。研究通过设计科学方法,对12名专家开展访谈、互动会话及问卷调查。结果表明,LLM能有效生成初始风险评估、识别潜在威胁并提供冗余校验;但需人工监督以确保准确性和合规性。尽管存在信任顾虑,专家仍愿在特定辅助角色中使用LLM,而非完全依赖其生成能力。本研究为安全关键领域工控系统的风险评估提供了基于LLM代理的可行方案。
原文摘要 · Abstract (English)
In safety-critical software systems, cybersecurity activities become essential, with risk assessment being one of the most critical. In many software teams, cybersecurity experts are either entirely absent or represented by only a small number of specialists. As a result, the workload for these experts becomes high, and software engineers would need to conduct cybersecurity activities themselves. This creates a need for a tool to support cybersecurity experts and engineers in evaluating vulnerabilities and threats during the risk assessment process. This paper explores the potential of leveraging locally hosted large language models (LLMs) with retrieval-augmented generation to support cybersecurity risk assessment in the forestry domain while complying with data protection and privacy requirements that limit external data sharing. We performed a design science study involving 12 experts in interviews, interactive sessions, and a survey within a large-scale project. The results demonstrate that LLMs can assist cybersecurity experts by generating initial risk assessments, identifying threats, and providing redundancy checks. The results also highlight the necessity for human oversight to ensure accuracy and compliance. Despite trust concerns, experts were willing to utilize LLMs in specific evaluation and assistance roles, rather than solely relying on their generative capabilities. This study provides insights that encourage the use of LLM-based agents to support the risk assessment process of cyber-physical systems in safety-critical domains.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。