arXiv論文メモ
新着一覧
cs.CR · 査読状況未確認

サイバー対処手順で使うAPI接続情報を共有する登録簿

CCR: Towards a Common, Quality-Gated CACAO Integrations Registry for European Cybersecurity Automation

Mateusz Zych, Vasileios Mavroeidis, Gudmund Grov

この論文をやさしく読む

ひとことで言うと

サイバー対処手順から製品のAPIを呼び出すための接続情報を、出所と検証結果付きで共有する登録簿を提案した。

何に役立つ?

異なる製品のAPI操作をCACAOの手順に結び付け、接続情報を再利用・点検する用途が考えられる。

この研究の面白いところ

機械的なAPI構造はルールで確実に変換し、言語モデルは活動名など限定的な意味付けに使う。採用基準と運用成熟度も分けている。

どこまで分かった?

ローカル環境で送信可能な要求を作れたのは675件。これが本番環境での動作や安全性を保証するという結果ではない。

v2のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

標準化され機械可読なサイバーセキュリティのプレイブックは、移植・共有・再利用できるインシデント対応の手順を支える。OASIS CACAOはプレイブックを特定の製品に依存しない形で表せるが、外部の製品やサービスを呼び出すための製品固有の接続情報までは提供しない。本研究は、CACAOのHTTP API接続情報をまとめる、出所を追跡できる公開登録簿Common CACAO Registry(CCR)を提案する。各接続情報にはAPI操作のコマンド、入力、対象、認証関連情報、出所、検証の根拠、成熟度のメタデータを記録する。 CCRには品質ゲートがあり、採用にはCACAO v2のスキーマに適合し、元のOpenAPI操作に照らす逆向き検証の平均点が0.8以上であることを求める。六段階の成熟度モデルは、より強い根拠が順に揃う様子を記録し、ゲートへの合格と運用可能な状態を区別する。CCRの初期データを作るため、OpenAPIからCACAOへの混合変換処理を開発した。決定的なプログラムが元の仕様に基づくインターフェース情報を抽出し、識別子を生成し、相互参照を結び、構造を検証する。一方、制約された言語モデルは操作名、認証の解釈、CACAOの活動注釈など、範囲を限定した意味情報を補う。 八つのセキュリティAPIの評価では、CACAOスキーマに適合する接続情報を713件生成し、逆向き検証の平均点は91.5%だった。このうち675件はローカルの実行環境で形式が整い送信可能なHTTP要求を作った。決定的なルール方式との比較では、機械的なAPI構造はルールによる変換のほうがより確実に保たれ、言語モデルは主としてCACAO活動注釈など限定された意味情報を補った。これらの結果は、CCRがCACAOの動作手順に再利用できる接続基盤となり、欧州のより広い共通登録簿の初期基盤となることを裏付ける。

v2の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-23(UTC)
最新改訂
2026-09-24 · v2
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Standardised, machine-readable cybersecurity playbooks provide a basis for portable, shareable, and reusable incident-response logic. OASIS CACAO provides a vendor-neutral representation for such playbooks, but not the product-specific integration artefacts needed to invoke external products and services. We introduce the Common CACAO Registry (CCR), an open, provenance-aware registry of CACAO HTTP-API connector envelopes. Each envelope captures an API operation's command, inputs, target, authentication-related information, provenance, validation evidence, and maturity metadata. CCR is quality-gated, with acceptance requiring both CACAO v2 schema validity and a mean back-validation score of at least 0.8 against the source OpenAPI operation, while a six-level maturity model records progressively stronger evidence and distinguishes gate acceptance from operational readiness. To seed CCR, we develop a hybrid OpenAPI-to-CACAO pipeline. Deterministic code extracts source-derived interface facts, generates identifiers, wires cross-references, and validates structure, while a constrained LLM provides bounded semantic enrichment, including action naming, authentication interpretation, and CACAO activity annotation. Evaluation across eight security APIs yields 713 CACAO-schema-valid envelopes with a mean back-validation score of 91.5%, of which 675 produce well-formed, dispatchable HTTP requests in a local harness. Comparison with a deterministic rule-based baseline shows that mechanical API structure is preserved more reliably through rule-based translation, while the LLM contributes bounded semantic enrichment, most notably CACAO activity annotation. Together, these results support CCR as reusable integration infrastructure for CACAO action steps and as an initial foundation for a broader common European registry.

著者のコメント

20 pages. Accepted at the 12th Workshop on the Security of Industrial Control Systems & of Cyber-Physical Systems (CyberICPS 2026), held in conjunction with ESORICS 2026. To appear in Springer LNCS

arXiv ID: 2609.27567 / 要約の誤りについて