불완전한 아키텍처에서 정량화된 위험으로: 다중 모드 LLM 기반 사이버 물리 시스템 보안 평가
From Incomplete Architecture to Quantified Risk: Multimodal LLM-Driven Security Assessment for Cyber-Physical Systems
사이버 물리 시스템은 종종 레거시 기술, 지식 관리 부족, 그리고 다양한 하위 시스템을 장기간 통합하는 복잡성으로 인해 불완전한 아키텍처 문서 또는 오래된 정보에 직면합니다. 이러한 아키텍처의 불완전성은 신뢰할 수 있는 보안 평가를 방해하며, 부정확하거나 누락된 아키텍처 정보는 시스템 의존성, 공격 표면, 그리고 위험 전파 경로를 식별하는 데 제한을 둡니다. 이러한 근본적인 문제를 해결하기 위해, 본 논문에서는 다중 모드 LLM으로 구동되는 프로토타입 도구에 구현된 아키텍처 중심 보안 위협 위험 평가 기술인 ASTRAL (Architecture-Centric Security Threat Risk Assessment using LLMs)을 소개합니다. 제안된 접근 방식은 문서가 단편적이거나 존재하지 않는 경우, 실무자가 CPS 아키텍처를 재구성하고 분석하는 데 도움을 줍니다. ASTRAL은 프롬프트 체이닝, few-shot 학습, 그리고 아키텍처 추론을 활용하여 다양한 데이터 소스에서 시스템 표현을 추출하고 합성합니다. LLM 추론을 아키텍처 모델링과 통합함으로써, 본 접근 방식은 사이버 물리 시스템에 대한 적응적인 위협 식별 및 정량적인 위험 추정을 지원합니다. 본 연구에서는 여러 CPS 사례 연구에 대한 ablation 연구와 14명의 숙련된 사이버 보안 전문가를 포함한 전문가 평가를 통해 접근 방식을 평가했습니다. 실무자 피드백에 따르면, ASTRAL은 아키텍처 중심 보안 평가를 지원하는 데 유용하고 신뢰할 수 있습니다. 전반적으로, 결과는 본 접근 방식이 더 정보에 입각한 사이버 위험 관리 결정을 내리는 데 기여할 수 있음을 시사합니다.
Cyber-physical systems often contend with incomplete architectural documentation or outdated information resulting from legacy technologies, knowledge management gaps, and the complexity of integrating diverse subsystems over extended operational lifecycles. This architectural incompleteness impedes reliable security assessment, as inaccurate or missing architectural knowledge limits the identification of system dependencies, attack surfaces, and risk propagation pathways. To address this foundational challenge, this paper introduces ASTRAL (Architecture-Centric Security Threat Risk Assessment using LLMs), an architecture-centric security assessment technique implemented in a prototype tool powered by multimodal LLMs. The proposed approach assists practitioners in reconstructing and analysing CPS architectures when documentation is fragmented or absent. By leveraging prompt chaining, few-shot learning, and architectural reasoning, ASTRAL extracts and synthesises system representations from disparate data sources. By integrating LLM reasoning with architectural modelling, our approach supports adaptive threat identification and quantitative risk estimation for cyber-physical systems. We evaluated the approach through an ablation study across multiple CPS case studies and an expert evaluation involving 14 experienced cybersecurity practitioners. Practitioner feedback suggests that ASTRAL is useful and reliable for supporting architecture-centric security assessment. Overall, the results indicate that the approach can support more informed cyber risk management decisions.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.