演示:tfdrift——一种用于基础设施漂移检测的严重性分类法和风险分类框架
Demo: tfdrift - A Severity Taxonomy and Risk Classification Framework for Infrastructure Drift Detection
浏览论文内容
中文总结 AI 辅助
针对IaC工具导致的配置漂移检测警报疲劳问题,提出tfdrift框架,通过四层级风险分类法筛选变更,在保留94%安全相关变更的同时降低73%警报量,为安全运维提供轻量方案。
中文摘要 AI 辅助
以Terraform为代表的基础设施即代码(IaC)工具已成为声明式云资源管理的标准,但配置漂移(即已部署的基础设施与声明状态出现偏差)仍是持续存在的运营与安全挑战。当前检测方法将所有变更同等对待,导致警报疲劳,使运维人员错过安全关键型修改。我们提出一种通用的基础设施漂移严重性分类法,基于资源类型和属性级影响将变更分为四个风险层级。我们将该分类法在tfdrift中实现,这是一个开源分类框架,包含60余项可配置规则,覆盖AWS、Azure和GCP的资源模式(此处报告的评估以AWS为重点)。对150余个AWS Terraform工作空间的评估显示,严重性筛选可将警报量降低73%,同时保留94%的安全相关变更,为基于机器学习的警报筛选提供了轻量型替代方案。tfdrift可通过此http链接获取。
英文摘要
Infrastructure as Code (IaC) tools like Terraform have become the standard for declarative cloud resource management, yet configuration drift, where deployed infrastructure diverges from its declared state, remains a persistent operational and security challenge. Current detection approaches treat all changes equivalently, contributing to alert fatigue that causes operators to miss security-critical modifications. We propose a generalized severity taxonomy for infrastructure drift that classifies changes into four risk tiers based on resource type and attribute-level impact. We implement this taxonomy in tfdrift, an open-source classification framework with 60+ configurable rules covering AWS, Azure, and GCP resource patterns (evaluation reported here is AWS-focused). Evaluation across 150+ AWS Terraform workspaces demonstrates that severity filtering reduces alert volume by 73% while retaining 94% of security-relevant changes, offering a lightweight alternative to ML-based alert filtering. tfdrift is available at github.com/sudarshan8417/tfdrift.