arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

为欧盟《网络弹性法案》准备AI增强型SIEM:从业者案例研究

Preparing an AI-Augmented SIEM for the EU Cyber Resilience Act: A Practitioner Case Study

Georgios Koutidis, Nikolaos Kekatos, Marina Korgiala-Karyda, Alexios Lekidis, Tom Nianios

arXiv 2610.07873首次发表:更新:

发表机构

Clone Systems; University of Thessaly(Clone Systems; 色萨利大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究通过SEUXDR案例,提出六步法将欧盟CRA法规转化为可操作准备,涵盖风险评估、漏洞报告及符合性评估,为中小企业提供可复制的合规路径。

AI 中文摘要

欧盟《网络弹性法案》(CRA),即(EU)2024/2847号法规,将产品网络安全规定为在欧盟市场上带有数字元素产品的生命周期义务:风险评估、漏洞处理、符合性文件以及第14条事件和漏洞报告准备必须在产品上市前就绪。构建安全产品的中小企业面临双重风险,因为其产品在范围内,而客户期望它们成为典范。本案例研究记录了针对此类产品SEUXDR的CRA准备试点,该产品是一个具有大型语言模型主动响应组件的AI增强型安全监控产品,基于开源CYBERFORT平台。我们贡献了一个可复现的六步配方(范围界定与分类、资产注册、生成证据、映射到CRA、差距与行动、审计包),两条端到端可追溯性线索,以及一个试点快照,将产品风险通过基线和AI特定控制与策略追溯到CRA目标。它为从业者提供了一个可复制的起点,用于将CRA法律文本转化为事件响应、漏洞报告和符合性评估的操作准备。

英文摘要

The EU Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, makes product cybersecurity a lifecycle obligation for products with digital elements on the EU market: risk assessment, vulnerability handling, conformity documentation, and Article 14 incident- and vulnerability-reporting readiness must be operational before market placement. Small and medium-sized enterprises that build security products are doubly exposed, since their products are in scope while their customers expect them to be exemplary. This case study documents a CRA preparedness pilot for one such product, SEUXDR, an AI-augmented security monitoring product with a large-language-model active-response component, on the open-source CYBERFORT platform. We contribute a reproducible six-step recipe (Scope and Classify, Asset Registration, Produce Evidence, Map to CRA, Gap and Actions, Audit Pack), two end-to-end traceability threads, and a pilot snapshot tracing product risks through baseline and AI-specific controls and policies to CRA objectives. It offers practitioners a replicable starting point for translating CRA legal text into operational preparedness for incident response, vulnerability reporting, and conformity assessment.

Comments7 pages, 2 figures, 2 tables. Accepted at the 2026 IEEE International Conference on Cyber Security and Resilience (IEEE CSR 2026)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑