统一整合多个安全工具,生成可量化系统安全评分。
A Unified Compliance Aggregator Framework for Automated Multi-Tool Security Assessment of Linux Systems

- 融合多种开源工具输出,统一为0-100分的综合安全分。
- 在不同加固等级下,分数随系统加固而提升,验证有效性。
- 适合运维与安全团队快速评估系统整体安全状态。
现代计算系统的安全评估通常需要使用多个专用工具,涵盖配置合规、文件完整性与漏洞暴露等不同方面,但其输出难以整合解读。本文提出统一合规聚合框架(UCA),将Lynis、OpenSCAP(STIG和CIS配置文件)、AIDE、Tripwire及Nmap NSE等工具集成,通过归一化处理将异构结果转换为0-100统一量纲,并采用加权聚合。针对文件完整性测量,引入对数评分模型以克服传统线性方法的局限性。实验在Ubuntu 22.04上进行,覆盖不同加固级别与环境。结果表明,随着系统加固,综合评分持续上升,且揭示了合规性与文件完整性工具之间的行为差异。两个案例研究——基础Web服务器与基于DVWA的系统——展示了该框架在实际场景中的应用价值。
原文摘要 · Abstract (English)
Assessing the security posture of modern computing systems typically requires the use of multiple specialized tools. These tools focus on different aspects such as configuration compliance, file integrity, and vulnerability exposure, and their outputs are often difficult to interpret collectively. This paper introduces the Unified Compliance Aggregator (UCA), a framework that integrates several open-source security tools into a single composite score representing overall system security. The proposed framework combines outputs from Lynis, OpenSCAP (STIG and CIS profiles), AIDE, Tripwire, and Nmap NSE. A normalization process converts heterogeneous outputs into a consistent 0 to 100 scale, followed by weighted aggregation. We also introduce a logarithmic scoring model for file integrity measurements to address limitations observed in prior linear approaches. Experiments were conducted on Ubuntu 22.04 across different hardening levels and environments. Results show consistent improvement in composite scores as systems are hardened, while also revealing contrasting behavior between compliance and file integrity tools. Two case studies, a basic web server and a DVWA-based system illustrate how the framework can be applied in practical scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。