预测安全评分修复效果,不暴露评分引擎秘密
Reliable Remediation Impact Prediction for Black-Box Security Ratings

- 用代理模型预测修复后评分,显式建模安全检查适用性
- 在5188个配置上提升预测准确率,可靠层识别不稳定预测
- 适合需要安全评分修复建议但不能泄露评分逻辑的机构
安全评分平台通过外部可观测的网络暴露面帮助组织优先修复漏洞。平台希望告知组织某项修复措施对其评分的影响,但频繁返回精确评分会暴露隐藏的评分机制。本文提出一种基于代理模型的修复评分影响预测方法,该方法在尊重评分引擎不可见性的前提下进行预测。代理模型从组织配置中预测评分,显式建模安全检查的适用性及已观测到的检查集合。主要挑战在于预测可靠性依赖于可观测检查证据的数量与结构。为此,方法结合了适用性感知的代理构建、受控检查限制下的敏感性分析、用于识别不稳定预测的可靠性层,以及对支持性修复动作的评分影响预测。显式建模检查适用性贯穿全程:既提升了评分预测性能,也为可靠性层提供了特征基础。在来自商业安全评分平台的5,188个组织配置的真实数据集上评估,结果表明适用性感知代理模型相比简单特征表示显著提升评分预测效果;对于修复建议,模型可预测支持动作的评分影响,可靠性层则帮助识别需谨慎解读的预测案例。
原文摘要 · Abstract (English)
Security rating platforms summarize externally observable cyber exposure and are expected to help organizations prioritize remediation. A platform may want to tell an organization how a candidate remediation action would affect its score, but repeatedly exposing exact score responses can reveal information about the hidden scoring engine. We propose a surrogate based approach for remediation score impact prediction that is designed to respect this opacity constraint. The surrogate predicts scores from organization configurations while explicitly representing checkpoint (i.e., a security check) applicability and the observed checkpoint set. A main challenge is that such predictions are not uniformly reliable: they depend on the amount and structure of the observable checkpoint evidence available for a given configuration. To address this, the approach combines applicability-aware surrogate construction, sensitivity analysis under controlled checkpoint restriction, a reliability layer for identifying unstable predictions, and score-impact prediction for supported remediation actions. Explicit modeling of checkpoint applicability is central throughout: it improves score prediction and provides the feature basis used by the reliability layer to identify unstable cases. We evaluate the approach on a real-world dataset of 5,188 organization configurations from a commercial security rating platform. The results show that the applicability-aware surrogate improves score prediction over simpler feature representations. For remediation, the surrogate predicts the score impact of supported actions, while the reliability layer helps identify cases in which these predicted impacts should be interpreted cautiously.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。