用多智能体框架自动推荐安全控制,少用资源也能高覆盖。
A Knowledge-Based Multi-Agent Framework for Security Control Recommendation
- 基于多智能体影响图建模安全决策,用在线学习找最优组合。
- 仅用约29%~65%的可控安全措施,实现73%~99%的防护覆盖。
- 适合缺乏安全专家的团队快速部署,响应速度低于36秒。
在缺乏足够网络安全专长的团队中,加固本地IT环境是一项艰巨任务。本文提出一种安全决策支持系统(Security DSS),在用户仅提供少量需求的前提下,推荐能覆盖不同安全维度的安全控制子族。系统基于来自知名信息安全与学术来源的统一数据集,将决策过程建模为非零和、同步的多智能体影响图(MAID)博弈,并通过无遗憾在线学习探索7个安全维度的决策空间,以最小化资源的不足与过度配置。实验验证了其在不同数据规模下的性能与准确性:当使用约65%的可实施安全控制时,可实现99%的满意度覆盖,耗时1.2-35.7秒;当使用约29%的控制时,覆盖率达73%-77%,耗时0.8-13.8秒。
原文摘要 · Abstract (English)
Hardening IT on-premises environments can be a daunting task for teams without access to adequate cybersecurity expertise. In this regard, Decision Support Systems (DSS) with embedded expert knowledge can assist users by guiding them with security recommendations to meet their objectives. This work proposes a Security DSS that recommends security control sub-families given minimal user requirements indicating coverage of different security dimensions. It leverages a curated, unified dataset from both well-known Information Security (InfoSec) and academic sources. This DSS is defined as a non-zero-sum, simultaneous game that is grounded in a Multi-Agent Influence Diagram (MAID) model and explores the decision space over 7 security dimensions or agents, using no-regret online learning to ultimately find the security control sub-families that best fit the requirements while incurring minimal under- and over-provisioning of security resources. This work was validated in terms of performance and accuracy, among others, for varying dataset sizes. It shows exceptional satisfaction coverage results of 99% when using as little as ~65% of the SW-implementable security controls, running in 1.2-35.7 seconds; and more moderate coverage results of 73%-77% when using ~29% of the controls, resolving in 0.8-13.8 seconds.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。