让AI主动理解资产风险,实现智能优先级排序。
AI Native Asset Intelligence

- 构建资产、身份、攻击路径的结构化模型,统一安全信号
- 分离暴露度与业务重要性,生成可比的资产评分(13万+资源)
- 适合企业级安全团队做主动风险研判与资源优先级管理
现代安全环境在云资源、身份、配置和第三方工具间产生碎片化信号。尽管AI安全助手提升了数据访问,但仍以被动响应为主,需用户精准提问并解析孤立结论,难以在企业环境中扩展。资产风险的优先级依赖于暴露程度、可利用性、依赖关系及业务上下文。重复的AI查询可能因缺乏结构化基准而产生不稳定的排序。本文提出AI原生资产智能框架,将异构安全数据转化为结构化情报层,支持一致、上下文相关且主动的资产级推理。该框架包含建模层(表示资产、身份、关系、控制、攻击向量、影响范围模式)与评分层,将碎片化信号转化为标准化的资产重要性度量。评分系统区分内在暴露度(基于误配置与攻击向量证据)与上下文重要性(基于异常、影响范围、业务关键性、数据关键性)。AI上下文化调整严重性与分类,确定性聚合保证一致性。我们在涵盖15家厂商、178种资产类型的生产快照中评估了该系统,共131,625个资源。敏感性分析与消融实验表明:严重性映射控制发现灵敏度,AI严重性调整优化优先级,攻击向量评分对罕见可利用性证据有响应,上下文调制则根据业务或数据重要性选择性修改暴露资产的优先级。结果支持该框架作为稳定排序与主动安全态势推理的基础。
原文摘要 · Abstract (English)
Modern security environments generate fragmented signals across cloud resources, identities, configurations, and third-party security tools. Although AI-native security assistants improve access to this data, they remain largely reactive: users must ask the right questions and interpret disconnected findings. This does not scale in enterprise environments, where signal importance depends on exposure, exploitability, dependencies, and business context. Repeated AI queries may therefore produce unstable prioritization without a structured basis for comparing assets. This paper introduces AI-native asset intelligence, a framework that transforms heterogeneous security data into a structured intelligence layer for consistent, contextual, and proactive asset-level reasoning. The framework combines a modeling layer, representing assets, identities, relationships, controls, attack vectors, and blast-radius patterns, with a scoring layer that converts fragmented signals into a normalized measure of asset importance. The scoring system separates intrinsic exposure, based on misconfigurations and attack-vector evidence, from contextual importance, based on anomaly, blast radius, business criticality, and data criticality. AI contextualization refines severity and business/data classifications, while deterministic aggregation preserves consistency. We evaluate the scoring system on a production snapshot with 131,625 resources across 15 vendors and 178 asset types. Sensitivity analyses and ablations show that severity mappings control finding sensitivity, AI severity adjustment refines prioritization, attack-vector scoring responds to rare exploitability evidence, and contextual modulation selectively modifies exposed resources based on business or data importance. The results support AI-native asset intelligence as a foundation for stable prioritization and proactive security-posture reasoning.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。