arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

GARAGE:基于大语言模型的攻击图生成中自动化边界的特征描述

GARAGE: Characterizing the Automation Boundary in LLM-based Attack Graph Generation

Daekwon Pi, Sangho Lee, Young Hun Lee, Huy Kang Kim

arXiv 2607.18108首次发表:更新:

AI 中文总结

研究针对现代车辆安全CTI合成难题,提出GARAGE框架,通过RAG技术将碎片化CTI转化为特定领域知识库用于攻击图生成,经实验验证能准确转移安全知识,还可作为TARA支持工具提供性价比分析以指导在各LLM层级部署。

AI 中文摘要

现代车辆安全依赖有效的网络威胁情报(CTI)合成,但当前自动化工具难以处理非结构化数据和汽车特定架构细微差别。为此引入GARAGE,一个由检索增强生成(RAG)驱动的框架,将碎片化CTI转换为可操作的特定领域知识库用于自动攻击图生成。它将包含12786个通用漏洞披露(CVE)和140个事件报告的数据集合成符合STIX 2.1和Auto-ISAC ATM的知识库。通过细致的杀伤链分析形式化战术模式级场景,实现威胁生成能力。320次留一法实验表明该框架能准确将安全知识转移到全新车辆架构。此外,将其定位为人工参与工作流程中可扩展的威胁评估与风险分析(TARA)支持工具,提供全面性价比分析以指导其在各LLM层级的部署。

英文摘要

While modern vehicle security depends on effective Cyber Threat Intelligence (CTI) synthesis, current automated tools struggle with unstructured data and automotive-specific architectural nuances. To bridge this gap, we introduce GARAGE, a RAG-powered framework that converts fragmented CTI into an actionable, domain-specific knowledge base for automated attack graph generation. GARAGE synthesizes a dataset of 12,786 CVEs and 140 incident reports into a STIX 2.1 and Auto-ISAC ATM-compliant knowledge base. By formalizing tactical-pattern-level scenarios through granular kill chain analysis, GARAGE achieves threat generation capabilities. Our 320 Leave-One-Out experiments reveal that the framework can accurately transfer security knowledge to entirely unseen vehicle architectures. Furthermore, we position GARAGE as a scalable TARA support tool within human-in-the-loop workflows, offering a comprehensive cost-performance analysis to guide its deployment across various LLM tiers.

Comments22 pages, 10 figures, 12 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑