arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.27567cs.CR

CCR:面向欧洲网络安全自动化的通用、质量门控CACAO集成注册表

CCR: Towards a Common, Quality-Gated CACAO Integrations Registry for European Cybersecurity Automation

Mateusz Zych, Vasileios Mavroeidis, Gudmund Grov

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出CCR,一个质量门控的CACAO集成注册表,通过混合流水线生成连接器信封,评估显示高验证分数,支持欧洲网络安全自动化。

中文摘要 AI 辅助

标准化、机器可读的网络安全剧本为可移植、可共享和可重用的事件响应逻辑提供了基础。OASIS CACAO为此类剧本提供了供应商中立的表示形式,但并未提供调用外部产品和服务所需的产品特定集成工件。我们引入了通用CACAO注册表(CCR),这是一个开放的、具有来源感知能力的CACAO HTTP-API连接器信封注册表。每个信封捕获API操作的命令、输入、目标、认证相关信息、来源、验证证据和成熟度元数据。CCR是质量门控的,其接受要求同时满足CACAO v2模式有效性和针对源OpenAPI操作的平均反向验证分数至少为0.8,而六级成熟度模型记录了逐步增强的证据,并区分了门控接受与操作就绪状态。为了填充CCR,我们开发了一个混合OpenAPI到CACAO的流水线。确定性代码提取源派生的接口事实,生成标识符,连接交叉引用,并验证结构,而受约束的LLM提供有界的语义增强,包括动作命名、认证解释和CACAO活动注释。对八个安全API的评估产生了713个符合CACAO模式的信封,平均反向验证分数为91.5%,其中675个在本地测试台中生成了格式良好、可调度的HTTP请求。与确定性基于规则的基线相比,机械API结构通过基于规则的翻译更可靠地保留,而LLM贡献了有界的语义增强,尤其是CACAO活动注释。总之,这些结果支持CCR作为CACAO操作步骤的可重用集成基础设施,并作为更广泛的欧洲通用注册表的初步基础。

英文摘要

Standardised, machine-readable cybersecurity playbooks provide a basis for portable, shareable, and reusable incident-response logic. OASIS CACAO provides a vendor-neutral representation for such playbooks, but not the product-specific integration artefacts needed to invoke external products and services. We introduce the Common CACAO Registry (CCR), an open, provenance-aware registry of CACAO HTTP-API connector envelopes. Each envelope captures an API operation's command, inputs, target, authentication-related information, provenance, validation evidence, and maturity metadata. CCR is quality-gated, with acceptance requiring both CACAO v2 schema validity and a mean back-validation score of at least 0.8 against the source OpenAPI operation, while a six-level maturity model records progressively stronger evidence and distinguishes gate acceptance from operational readiness. To seed CCR, we develop a hybrid OpenAPI-to-CACAO pipeline. Deterministic code extracts source-derived interface facts, generates identifiers, wires cross-references, and validates structure, while a constrained LLM provides bounded semantic enrichment, including action naming, authentication interpretation, and CACAO activity annotation. Evaluation across eight security APIs yields 713 CACAO-schema-valid envelopes with a mean back-validation score of 91.5%, of which 675 produce well-formed, dispatchable HTTP requests in a local harness. Comparison with a deterministic rule-based baseline shows that mechanical API structure is preserved more reliably through rule-based translation, while the LLM contributes bounded semantic enrichment, most notably CACAO activity annotation. Together, these results support CCR as reusable integration infrastructure for CACAO action steps and as an initial foundation for a broader common European registry.

发表机构

  • Cyentific AS(Cyentific公司)
  • Department of Informatics, University of Oslo(奥斯陆大学信息学系)
  • Norwegian Defence Research Establishment(挪威国防研究所)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑