arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

从待办事项到安全指南:迈向持续安全合规

From Backlog Items to Security Guidance: Towards Continuous Security Compliance

Ignacio García Núñez, Florian Angermeir, Fabiola Moyón Constante

arXiv 2607.27374首次发表:更新:

发表机构

Technical University of Munich; fortiss; Blekinge Institute of Technology; Siemens Technology(慕尼黑工业大学; fortiss研究所; 布莱金厄理工学院; 西门子技术)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究针对受监管领域持续软件工程中待办事项安全要求明确困难的问题,提出基于NLP的待办事项丰富系统,结合分类器与RAG管道,发布标注数据集,经评估可有效检测安全相关待办事项并关联安全要求,助力持续安全合规。

AI 中文摘要

受监管领域的持续软件工程要求工程团队在整个开发生命周期中处理安全问题,但在待办事项中明确安全要求仍存在问题。工程师必须从简短、自由格式的描述中推断待办事项的安全相关性,且往往缺乏适用要求的及时指导。本文提出一种基于NLP的待办事项丰富系统,可检测与安全相关的待办事项并将其链接到相关安全要求,该方法将安全相关性分类器与针对安全要求文档的检索增强生成(RAG)管道相结合。该方法在一家受高度监管领域的大型企业环境中开发并评估,本文提出三项贡献:第一,发布了一个由9名安全从业者标注安全相关性的288个待办事项数据集,标注间存在实质性一致性(Fleiss' κ=0.787);第二,一个面向召回的分类器在分布内实现F2=0.774,在5个既定基准上的平均零样本G-度量约为0.65,与大多数已发表的经典机器学习及开源GPT基线相当或更优;第三,本文对一个四阶段、基于安全要求文档的RAG管道进行了初步评估,2名从业者使用公司内部安全政策和CIS基准对工业待办事项进行评估,在检索到的24条条款中,12条的相关性评分至少为4/5。研究结果首次表明,基于NLP的产品待办事项丰富可支持工程师在开发过程早期识别安全要求,本研究旨在通过在持续软件工程中主动引入安全要求,促进持续安全合规。

英文摘要

Continuous software engineering in regulated domains requires engineering teams to address security throughout the development lifecycle. Yet making security requirements explicit in backlog items is still problematic. Engineers must instead infer security relevance of backlog items from brief, free-form descriptions and often lack timely guidance on applicable requirements. We present an NLP-based backlog enrichment system that detects security-relevant backlog items and links them to relevant security requirements. The approach combines a security-relevance classifier with a retrieval-augmented generation (RAG) pipeline over security requirements documents. The approach was developed and evaluated in the context of a large enterprise in highly regulated domains. We present three contributions. First, we release a dataset of 288 backlog items labeled for security relevance by nine security practitioners, with substantial agreement (Fleiss' $κ=0.787$). Second, a recall-oriented classifier achieving $F2=0.774$ in-distribution and mean zero-shot G-measure $\approx 0.65$ across five established benchmarks, matching or outperforming most published classical-ML and open-source GPT baselines. Third, we preliminarily evaluated a four-stage security requirements document-grounded RAG pipeline with two practitioners on industrial backlogs using company-internal security policies and CIS Benchmarks. Of the retrieved 24 clauses, 12 were rated at least 4/5 for relevance. Our findings provide first indicators that NLP-based product backlog enrichment can support engineers in identifying security requirements early in the development process. With this work we aim to facilitate continuous security compliance through proactive introduction of security requirements in continuous software engineering.

Comments11 pages, 3 figures, 3 tables. Camera-ready version, accepted at the 41st IEEE/ACM International Conference on Automated Software Engineering (ASE 2026), Industry Showcase track, Munich, Germany, October 2026. v2 replaces the originally submitted version with the camera-ready: corrected bibliography entries and added figure descriptions; no changes to results or claims

DOI:10.1145/3832783.3834527

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑