Cloud Security Posture Management (CSPM) systems detect known vulnerabilities by maintaining a rule set, distributing it to customers, and evaluating it against periodically-collected asset inventories. To our knowledge, in publicly documented architectures the rule set is environment-agnostic and curated centrally by the vendor; updates are batched into release cycles and shipped on a cadence ranging from hours to days depending on detection severity. The disclosure-to-protection window -- from a CVE being published to the customer's system being capable of detecting affected assets -- is therefore bounded by the vendor's release cadence for version-match detections, and by additional human authoring time for richer detections incorporating configuration predicates beyond the affected-software string. We propose an architecture in which the rule set is not vendor-distributed but continuously derived, within the customer's tenant, from the intersection of public catalogue feeds and the live asset graph. A rule comes into existence when a catalogue entry and an applicable asset are simultaneously present, and goes out of existence when either input ceases to support it. Derivation is bidirectional: new catalogue entries and new assets both trigger it. It incorporates the full structured-field content of catalogue entries, not only the affected-software predicate. The live rule set is bounded by environment diversity rather than catalogue breadth. Prior systems incrementally evaluate a static rule set; we incrementally derive the rule set itself. We present the threat model, the architecture, formal semantics with an equivalence theorem, complexity analysis, a worked example, and an evaluation methodology. The contribution is the architectural shift and its latency and resource consequences; rule correctness and alert prioritization are out of scope.
翻译:云安全态势管理(CSPM)系统通过维护规则集、将其分发给客户,并依据定期收集的资产清单进行检测,从而识别已知漏洞。据我们所知,在公开记载的架构中,规则集与环境无关,由供应商集中管理;更新被批量整合到发布周期中,并根据检测严重性以数小时到数天的节奏进行交付。因此,从CVE发布到客户系统能够检测受影响资产的披露到保护窗口,受限于供应商版本匹配检测的发布周期,以及针对包含受影响软件字符串之外配置谓词的更复杂检测所需的人工编写时间。我们提出一种架构,其中规则集并非由供应商分发,而是在客户租户内,通过公共目录源与实时资产图谱的交集持续派生。当目录条目与适用资产同时存在时,规则即产生;当任一输入不再支持时,规则则消失。派生是双向的:新目录条目和新资产均可触发派生。该过程整合了目录条目的完整结构化字段内容,而不仅限于受影响软件谓词。实时规则集的范围受限于环境多样性而非目录广度。先前系统增量评估静态规则集;而我们则增量派生规则集本身。我们介绍了威胁模型、架构、包含等价定理的形式语义、复杂度分析、工作实例及评估方法。本文贡献在于架构转变及其延迟与资源影响;规则正确性与警报优先级不在讨论范围内。