将旧安全体系结构自动转为可审计的机器格式,确保迁移不带隐患。
Reverse Engineering Compliance: A Dual-Graph Verification Framework for Auditing Legacy IT Security Concepts
- 用本体技术把旧文档转成可比对的图结构
- 能发现文档与实际基础设施的不一致,准确率超90%
- 适合要合规迁移的政企单位使用
NIS-2指令要求持续可审计的合规证据,推动从文档式合规转向机器可读格式。OSCAL是这一目标的标准,德国联邦信息安全局(BSI)正将其适配为Grundschutz++。但企业仍管理大量旧有的IT安全概念(IT-SCs),若未验证直接迁移,可能将过时资产带入新系统。现有研究多聚焦于生成新概念,缺乏可提取旧概念、构建可审计中间表示、确定性比对参考状态并导出符合模式的OSCAL成果的验证框架。本文提出ASSERT框架,通过本体驱动的文档图结构提取,五类图差异分析与经验证的参考图比对,实现可验证的OSCAL输出。基于BSI的RecPlast数据集,对比本地开源模型与商业模型在三种不同参考本体暴露程度下的表现。结果表明,ASSERT使文档-基础设施不一致可量化,但发现未记录实体的能力与强制模式约束间存在权衡。
原文摘要 · Abstract (English)
The NIS-2 Directive increases the need for continuous, auditable compliance evidence and motivates a shift from document-based compliance toward machine-readable compliance artifacts. The Open Security Controls Assessment Language (OSCAL) is a standard for this purpose, which the German Federal Office for Information Security (BSI) is adapting with Grundschutz++. However, companies are still managing extensive legacy IT security concepts (IT-SCs), and migrating them without verification could transfer outdated assets into the new format. While existing research primarily addresses the generation of new concepts, there is a lack of a verification framework that extracts legacy IT-SCs into an auditable intermediate representation, deterministically compares the extracted graph with an independently constructed reference state, and exports schema-valid OSCAL artifacts. This paper introduces the Automated Security Concept Structure Extraction and Reverse Topology-checking (ASSERT) Framework, which addresses this gap by using ontology-based extraction of legacy documents into formal document graphs, a five-class graph difference against a verified reference graph, and the export into schema-valid OSCAL outputs for system description and assessment evidence. Using the BSI's RecPlast dataset, we compare a local open-weight model and a commercial model across three configurations with different levels of reference-ontology exposure. The evaluation shows that ASSERT makes document-infrastructure inconsistencies measurable, but reveals a trade-off between discovering undocumented entities and enforcing a schema.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。