Cloud Security Posture Management (CSPM) systems detect known vulnerabilities by maintaining a rule set, distributing it to customers, and evaluating it against periodically-collected asset inventories. To our knowledge, in publicly documented architectures the rule set is environment-agnostic and curated centrally by the vendor; updates are batched into release cycles and shipped on a cadence ranging from hours to days depending on detection severity. The disclosure-to-protection window -- from a CVE being published to the customer's system being capable of detecting affected assets -- is therefore bounded by the vendor's release cadence for version-match detections, and by additional human authoring time for richer detections incorporating configuration predicates beyond the affected-software string. We propose an architecture in which the rule set is not vendor-distributed but continuously derived, within the customer's tenant, from the intersection of public catalogue feeds and the live asset graph. A rule comes into existence when a catalogue entry and an applicable asset are simultaneously present, and goes out of existence when either input ceases to support it. Derivation is bidirectional: new catalogue entries and new assets both trigger it. It incorporates the full structured-field content of catalogue entries, not only the affected-software predicate. The live rule set is bounded by environment diversity rather than catalogue breadth. Prior systems incrementally evaluate a static rule set; we incrementally derive the rule set itself. We present the threat model, the architecture, formal semantics with an equivalence theorem, complexity analysis, a worked example, and an evaluation methodology. The contribution is the architectural shift and its latency and resource consequences; rule correctness and alert prioritization are out of scope.


翻译:云安全态势管理(CSPM)系统通过维护规则集、将其分发给客户,并依据定期收集的资产清单进行检测,从而识别已知漏洞。据我们所知,在公开记载的架构中,规则集与环境无关,由供应商集中管理;更新被批量整合到发布周期中,并根据检测严重性以数小时到数天的节奏进行交付。因此,从CVE发布到客户系统能够检测受影响资产的披露到保护窗口,受限于供应商版本匹配检测的发布周期,以及针对包含受影响软件字符串之外配置谓词的更复杂检测所需的人工编写时间。我们提出一种架构,其中规则集并非由供应商分发,而是在客户租户内,通过公共目录源与实时资产图谱的交集持续派生。当目录条目与适用资产同时存在时,规则即产生;当任一输入不再支持时,规则则消失。派生是双向的:新目录条目和新资产均可触发派生。该过程整合了目录条目的完整结构化字段内容,而不仅限于受影响软件谓词。实时规则集的范围受限于环境多样性而非目录广度。先前系统增量评估静态规则集;而我们则增量派生规则集本身。我们介绍了威胁模型、架构、包含等价定理的形式语义、复杂度分析、工作实例及评估方法。本文贡献在于架构转变及其延迟与资源影响;规则正确性与警报优先级不在讨论范围内。

0
下载
关闭预览

相关内容

《量子云系统安全漏洞:新兴威胁综述》最新综述
专知会员服务
16+阅读 · 2025年5月2日
《边缘云异常检测的机器学习》最新博士论文
专知会员服务
28+阅读 · 2024年8月8日
《物联网在危机管理中的应用》2023最新137页论文
专知会员服务
29+阅读 · 2023年9月7日
腾讯等发布《2023产业互联网安全十大趋势》报告,26页pdf
【Manning新书】云计算安全指南:以AWS为例,311页pdf
专知会员服务
40+阅读 · 2022年9月11日
《信息安全技术 云计算服务安全指南》国家标准意见稿
专知会员服务
33+阅读 · 2022年4月14日
专知会员服务
36+阅读 · 2021年10月17日
《人工智能安全测评白皮书》,99页pdf
专知
36+阅读 · 2022年2月26日
Xsser 一款自动检测XSS漏洞工具
黑白之道
14+阅读 · 2019年8月26日
网络安全态势感知
计算机与网络安全
26+阅读 · 2018年10月14日
网络安全态势感知浅析
计算机与网络安全
18+阅读 · 2017年10月13日
国家自然科学基金
3+阅读 · 2015年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
VIP会员
最新内容
分层反无人机系统发展新趋势
专知会员服务
8+阅读 · 9月3日
何为协作武器?
专知会员服务
10+阅读 · 9月1日
《理解认知战:超越信息》
专知会员服务
14+阅读 · 9月1日
美国战争部在GenAI.mil上推出OpenAI的ChatGPT Mil
专知会员服务
10+阅读 · 8月31日
人工智能赋能军事维护:重新定义国防战备
专知会员服务
5+阅读 · 8月31日
相关基金
国家自然科学基金
3+阅读 · 2015年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员