arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

第三方云安全发现的语境化

Contextualization of Third-Party Cloud Security Findings

Leon Goldberg, Gal Engelberg

arXiv 2610.08895首次发表:更新:

发表机构

Sola Security(Sola Security)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对第三方云安全发现严重性静态、缺乏环境上下文的问题,提出语境化方法,用深度研究智能体基于跨信号资产图重推导严重性,现场研究显示四分之三发现被重新分级,且99.4%判定有实证支持。

AI 中文摘要

发现严重性是安全团队确定修复优先级的主要驱动因素。对于第三方云安全发现,该严重性是静态的:触发该发现的规则在规则遇到任何环境之前就为其分配了严重性,因此它反映的是该条件在一般情况下的风险,而非该发现对其所在具体环境构成的风险。评分标准定义了环境特定上下文应归属的位置。该上下文在生产环境中能在多大程度上改变发现严重性、决定性证据位于何处,以及它是否经得起真实环境的检验,这些尚未被量化测量。我们通过语境化来解决这一空白,即根据发现所在环境中的证据重新推导每个发现的严重性。一个基于预计算跨信号资产图的深度研究智能体,会针对每个发现调查资源的状态、其图邻域以及其他产品的信号,并返回带有证据链的调整后严重性。我们在一个生产现场研究中对其进行了评估,该研究涵盖来自两个商业云安全平台的9,967个供应商高危发现,分布于八个真实生产环境中,评估标准有三条:每个判定背后事实对真实环境的忠实度、每个决策对标记资源之外上下文的依赖程度,以及推理的规律性。四分之三的发现被重新分级,大多为降级,且同一规则在单个环境内常常朝相反方向变动。约一半的决定性证据位于标记资源之外,对真实基础设施的只读探测确认了99.4%已判定发现的决定性事实。

英文摘要

Finding severity is the main driver of how security teams prioritize remediation. For third-party cloud security findings, that severity is static: the rule that raised the finding assigns it before the rule meets any environment, so it reflects the risk of the condition in general rather than the risk the finding poses to the concrete environment where it lives. Scoring standards define where environment-specific context belongs. How far that context changes finding severities in production, where the deciding evidence lies, and whether it holds against the live environment have not been measured. We address this gap with contextualization, re-deriving each finding's severity from evidence in the environment where the finding lives. A deep research agent over a precomputed cross-signal asset graph investigates each finding against the resource's state, its graph neighborhood, and other products' signals, and returns an adjusted severity with an evidence trace. We evaluate it in a production field study of 9,967 vendor HIGH findings from two commercial cloud security platforms across eight real production environments, on three criteria: the faithfulness of the facts behind each verdict to the live environment, the dependence of each decision on context beyond the flagged resource, and the regularity of the reasoning. Three in four findings are re-graded, mostly downward, and the same rule often moves in opposite directions inside a single environment. About half of the decisive evidence lies beyond the flagged resource, and read-only probes of live infrastructure confirm the decisive fact for 99.4% of decided findings.

Comments11 pages, 1 figure, 2 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑