黑盒安全评级的可靠修复影响预测
Reliable Remediation Impact Prediction for Black-Box Security Ratings
浏览论文内容
中文总结 AI 辅助
研究针对黑盒安全评级中预测修复影响的问题,提出基于代理的方法,结合适用性感知代理构建、敏感性分析、可靠性层等,在真实数据集上评估,能更好预测分数,助于识别需谨慎解释预测影响的情况。
中文摘要 AI 辅助
安全评级平台总结外部可观察到的网络暴露情况,旨在帮助组织确定修复优先级。平台可能想告知组织候选修复行动对其分数的影响,但反复暴露确切分数响应会泄露隐藏评分引擎的信息。我们提出一种基于代理的方法来预测修复分数影响,该方法旨在遵守这种不透明性约束。代理从组织配置预测分数,同时明确表示检查点适用性和观察到的检查点集。主要挑战在于此类预测并非始终可靠,其取决于给定配置可用的可观察检查点证据的数量和结构。为解决此问题,该方法结合了适用性感知代理构建、受控检查点限制下的敏感性分析、用于识别不稳定预测的可靠性层以及对支持的修复行动的分数影响预测。检查点适用性的显式建模贯穿始终:它改善分数预测,并为可靠性层提供用于识别不稳定情况的特征基础。我们在来自商业安全评级平台的5188个组织配置的真实数据集上评估该方法。结果表明,适用性感知代理比简单特征表示能更好地预测分数。对于修复,代理预测支持行动的分数影响,而可靠性层有助于识别应谨慎解释这些预测影响的情况。
英文摘要
Security rating platforms summarize externally observable cyber exposure and are expected to help organizations prioritize remediation. A platform may want to tell an organization how a candidate remediation action would affect its score, but repeatedly exposing exact score responses can reveal information about the hidden scoring engine. We propose a surrogate based approach for remediation score impact prediction that is designed to respect this opacity constraint. The surrogate predicts scores from organization configurations while explicitly representing checkpoint (i.e., a security check) applicability and the observed checkpoint set. A main challenge is that such predictions are not uniformly reliable: they depend on the amount and structure of the observable checkpoint evidence available for a given configuration. To address this, the approach combines applicability-aware surrogate construction, sensitivity analysis under controlled checkpoint restriction, a reliability layer for identifying unstable predictions, and score-impact prediction for supported remediation actions. Explicit modeling of checkpoint applicability is central throughout: it improves score prediction and provides the feature basis used by the reliability layer to identify unstable cases. We evaluate the approach on a real-world dataset of 5,188 organization configurations from a commercial security rating platform. The results show that the applicability-aware surrogate improves score prediction over simpler feature representations. For remediation, the surrogate predicts the score impact of supported actions, while the reliability layer helps identify cases in which these predicted impacts should be interpreted cautiously.
发表机构
- Telecom SudParis(电信 SudParis)
- Institut Polytechnique de Paris(巴黎理工学院)
- SAMOVAR
机构由 AI 辅助整理,请以论文原文为准。