arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ThreatForest:基于可插拔TTP框架映射的多智能体攻击树生成方法

ThreatForest: Multi-Agent Attack Tree Generation with Pluggable TTP Framework Mapping

Cristian Leo, Anton Dykyi, Danny Cortegaca, Daniel Begimher, Prakash Jha

arXiv 2607.27528首次发表:更新:

发表机构

Amazon Web Services, Inc.; Amazon Web Services EMEA SARL, UK Branch(亚马逊网络服务公司; 亚马逊网络服务欧洲、中东及非洲有限责任公司英国分部)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

ThreatForest是首个将代码仓库转化为带TTP映射攻击树及对应缓解措施的端到端多智能体系统,其嵌入编码器是TTP映射准确率的核心瓶颈,相关基准框架可用于同类系统测试。

AI 中文摘要

威胁建模对安全软件开发至关重要,但对云原生架构的手动分析速度缓慢且需要稀缺的安全专业知识。我们提出了ThreatForest,这是一种多智能体系统,可从源代码仓库生成结构化攻击树,将攻击步骤映射到可插拔框架(MITRE ATT&CK、CAPEC以及云特定威胁矩阵)中的对手战术、技术和程序(TTP),并综合可行的缓解措施。ThreatForest将威胁建模分解为多阶段智能体流水线——仓库分析、上下文细化、威胁生成、带TTP映射的并行攻击树构建与缓解措施综合,以及报告生成——这些阶段被编排为带有确定性验证门、有限重试和三个人工在环验证点的有向图。一个领域特定的Sentence-Transformer通过余弦相似度将每个攻击步骤映射到候选技术;我们经验性地表明,嵌入阶段而非周围流水线是主要的准确率瓶颈。我们在16维 rubric 上针对七个应用领域评估ThreatForest,由一组独立LLM评分者评分,评分过程包含对抗性验证和专家评审。针对威胁陈述、攻击树和缓解措施,小组测量的质量达到0.63-0.68(0-1分制),但仅针对仅嵌入的TTP映射达到0.29——该差距在所有七个领域均稳定存在,确定了核心约束。在同一模型上的受控单调用基线使映射防御能力提高了一倍以上,将限制因素锁定在嵌入编码器而非多智能体设计。据我们所知,ThreatForest是首个将代码仓库转化为跨对手框架的带TTP映射攻击树并提供基于证据的缓解措施的端到端系统,且具备可重复使用的此类系统基准测试框架。

英文摘要

Threat modeling is essential for secure software development, yet manual analysis of cloud-native architectures is slow and demands scarce security expertise. We present ThreatForest, a multi-agent system that generates structured attack trees from source code repositories, maps attack steps to adversary tactics, techniques, and procedures (TTPs) from a pluggable set of frameworks (MITRE ATT&CK, CAPEC, and cloud-specific threat matrices), and synthesizes actionable mitigations. ThreatForest decomposes threat modeling into a multi-stage agent pipeline -- repository analysis, context refinement, threat generation, parallel attack-tree construction with TTP mapping and mitigation synthesis, and report generation -- orchestrated as a directed graph with deterministic verification gates, bounded retries, and three human-in-the-loop validation points. A domain-specific sentence-transformer maps each attack step to candidate techniques by cosine similarity; we show empirically that this embedding stage, not the surrounding pipeline, is the dominant accuracy bottleneck. We evaluate ThreatForest across seven application domains on a sixteen-dimension rubric, scored by a panel of independent LLM raters with an adversarial verification pass and expert review. Panel-measured quality reaches 0.63-0.68 (on a 0-1 scale) for threat statements, attack trees, and mitigations, but only 0.29 for embedding-only TTP mapping -- a gap stable across all seven domains that isolates the binding constraint. A controlled single-call baseline on the same model more than doubles mapping defensibility, pinning the limitation on the embedding encoder rather than the multi-agent design. To our knowledge, ThreatForest is the first end-to-end system that turns a code repository into TTP-mapped attack trees with evidence-based mitigations across adversary frameworks, with a reusable framework for benchmarking such systems.

Comments20 pages, 12 tables, 1 figure

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑