用统一框架整合多种安全检测工具,提升服务器合规评估的准确性与可复现性。
Security Hardening Using FABRIC: Implementing a Unified Compliance Aggregator for Linux Servers
- 构建统一合规聚合器,标准化不同工具输出并加权融合
- 全加固下OpenSCAP合规率从39.7升至71.8,自定义规则达83.6%
- 适合需要系统化评估服务器安全加固效果的研究者与运维团队
本文提出一个统一框架,通过在FABRIC测试平台聚合异构安全审计工具,评估Linux服务器的安全加固水平。实验部署了三个配置为基线、部分和完全加固的Ubuntu 22.04节点,使用Lynis、OpenSCAP和AIDE进行了108次审计。针对各工具间解释不一致的问题,实现统一合规聚合器(UCA),解析输出、归一化得分至0–100分制,并结合可定制规则引擎生成加权指标。实验表明,完全加固使OpenSCAP合规率从39.7提升至71.8,自定义规则合规率从39.3%提高到83.6%。结果证明,UCA相比单一工具能提供更清晰、可复现的安全态势评估,支持在可编程测试环境中系统化评价加固有效性。
原文摘要 · Abstract (English)
This paper presents a unified framework for evaluating Linux security hardening on the FABRIC testbed through aggregation of heterogeneous security auditing tools. We deploy three Ubuntu 22.04 nodes configured at baseline, partial, and full hardening levels, and evaluate them using Lynis, OpenSCAP, and AIDE across 108 audit runs. To address the lack of a consistent interpretation across tools, we implement a Unified Compliance Aggregator (UCA) that parses tool outputs, normalizes scores to a common 0--100 scale, and combines them into a weighted metric augmented by a customizable rule engine for organization-specific security policies. Experimental results show that full hardening increases OpenSCAP compliance from 39.7 to 71.8, while custom rule compliance improves from 39.3\% to 83.6\%. The results demonstrate that UCA provides a clearer and more reproducible assessment of security posture than individual tools alone, enabling systematic evaluation of hardening effectiveness in programmable testbed environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。