发表机构
Department of Mathematics and Computer Science(数学与计算机科学系)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
研究针对公司遗留IT安全概念缺乏验证框架的问题,提出ASSERT框架,通过本体提取、图差异比较等方法,将其提取为可审计中间表示并导出有效OSCAL工件,实验显示该框架可测文档不一致性,但存在权衡。
AI 中文摘要
NIS-2指令增加了对持续可审计合规证据的需求,促使从基于文档的合规转向机器可读的合规工件。开放安全控制评估语言(OSCAL)是为此目的的标准,德国联邦信息安全办公室(BSI)正在用Grundschutz++进行适配。然而,公司仍在管理大量遗留IT安全概念(IT-SCs),未经验证迁移可能会将过时资产转移到新格式。现有研究主要关注新概念的生成,缺乏一个验证框架。本文介绍了自动化安全概念结构提取和逆向拓扑检查(ASSERT)框架,通过基于本体将遗留文档提取到正式文档图中,与已验证的参考图进行五类图差异比较,并导出符合模式的OSCAL输出。使用BSI的RecPlast数据集进行比较,评估表明ASSERT使文档基础设施不一致性可测量,但揭示了在发现未记录实体和执行模式之间的权衡。
英文摘要
The NIS-2 Directive increases the need for continuous, auditable compliance evidence and motivates a shift from document-based compliance toward machine-readable compliance artifacts. The Open Security Controls Assessment Language (OSCAL) is a standard for this purpose, which the German Federal Office for Information Security (BSI) is adapting with Grundschutz++. However, companies are still managing extensive legacy IT security concepts (IT-SCs), and migrating them without verification could transfer outdated assets into the new format. While existing research primarily addresses the generation of new concepts, there is a lack of a verification framework that extracts legacy IT-SCs into an auditable intermediate representation, deterministically compares the extracted graph with an independently constructed reference state, and exports schema-valid OSCAL artifacts. This paper introduces the Automated Security Concept Structure Extraction and Reverse Topology-checking (ASSERT) Framework, which addresses this gap by using ontology-based extraction of legacy documents into formal document graphs, a five-class graph difference against a verified reference graph, and the export into schema-valid OSCAL outputs for system description and assessment evidence. Using the BSI's RecPlast dataset, we compare a local open-weight model and a commercial model across three configurations with different levels of reference-ontology exposure. The evaluation shows that ASSERT makes document-infrastructure inconsistencies measurable, but reveals a trade-off between discovering undocumented entities and enforcing a schema.
CommentsAccepted for publication at the 2026 IEEE International Conference on Computer, Information and Telecommunication Systems (IEEE CITS), Piraeus-Athens, Greece, July 22-24, 2026. 8 pages, 1 figure
DOI:10.1109/CITS70307.2026.11637193