Layered cybersecurity pipelines transform evidence before they decide on it, and the order of those transformations determines which security facts become visible to which layer. This paper gives layer order a finite-state semantics built from a layer-order automaton, deterministic sequential security transducers, evidence markers, and a final decision automaton. The worked case is HTTP request desynchronization: front-end and back-end processors compute incompatible request boundaries, and the same trace is detected or missed according to whether framing evidence reaches the parser-differential layer before it commits. The results separate completed-trace recognition, online editing, decision synthesis, and faithful enforcement; characterize faithful online enforcement as the regular prefix-closed case under causal visibility; and show that regular policies beyond that boundary remain recognizable without becoming deployable enforcers. The framework is monolithically equivalent to finite-output deterministic edit automata, while preserving layer-local invariants such as marker birth, marker survival, and reorder-sensitive visibility. A concrete parser-pair semantics identifies the forbidden marker factor with CL.TE, TE.CL, TE.TE, and HTTP/2-downgrade boundary disagreement under the stated abstraction, and a contextual reorder congruence classifies which component permutations induce the same decision language. The result is an automata-theoretic account of order-sensitive security failures and a compositional vocabulary for auditing, synthesizing, and comparing layered enforcement pipelines.
翻译:分层网络安全管道在对证据做出决策前会对其进行转换,而转换的顺序决定了哪些安全事实能被哪一层可见。本文为层级顺序赋予了一种基于层级顺序自动机、确定性顺序安全转换器、证据标记和最终决策自动机的有限状态语义。具体案例研究是HTTP请求反同步:前端和后端处理器计算出不兼容的请求边界,根据帧证据是否在parser-differential层提交之前到达该层,同一跟踪序列可能被检测到或遗漏。研究结果区分了完整跟踪识别、在线编辑、决策合成和忠实执行;将忠实在线执行刻画为因果可见性下的正则前缀封闭情形;并表明超出该边界的正则策略依然可识别但无法成为可部署的执行器。该框架在整体上等价于有限输出确定性编辑自动机,同时保留了标记生成、标记存活和重排敏感可见性等层级局部不变量。具体的解析器对语义将禁止的标记因子与CL.TE、TE.CL、TE.TE及HTTP/2降级边界不一致性关联到所述抽象层次上,而上下文重排同余类别则划分出哪些组件排列会诱导相同的决策语言。研究结果为顺序敏感型安全失效提供了一种自动机理论解释,并为审计、综合和比较分层执行管道提供了组合式词汇表。