Automated Implementation of Windows-related Security-Configuration Guides
Patrick Stöckle, Bernd Grobauer, Alexander Pretschner
Abstract
Hardening is the process of configuring IT systems to ensure the security of the systems' components and data they process or store. The complexity of contemporary IT infrastructures, however, renders manual security hardening and maintenance a daunting task. In many organizations, security-configuration guides expressed in the SCAP (Security Content Automation Protocol) are used as a basis for hardening, but these guides by themselves provide no means for automatically implementing the required configurations. In this paper, we propose an approach to automatically extract the relevant information from publicly available security-configuration guides for Windows operating systems using natural language processing. In a second step, the extracted information is verified using the information of available settings stored in the Windows Administrative Template files, in which the majority of Windows configuration settings is defined. We show that our implementation of this approach can extract and implement 83% of the rules without any manual effort and 96% with minimal manual effort. Furthermore, we conduct a study with 12 state-of-the-art guides consisting of 2014 rules with automatic checks and show that our tooling can implement at least 97% of them correctly. We have thus significantly reduced the effort of securing systems based on existing security-configuration guides.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on1
Related papers
- PracExtractor: Extracting Configuration Good Practices from Manuals to Detect Server MisconfigurationsChengcheng Xiang, Haochen Huang, Andrew Yoo, Yuanyuan Zhou et al.USENIX ATC 2020 · 24 citations
- SCPatcher: Mining Crowd Security Discussions to Enrich Secure Coding PracticesZiyou Jiang, Lin Shi, Guowei Yang, Qing WangASE 2023 · 2 citations
- If It's Not Secure, It Should Not Compile: Preventing DOM-Based XSS in Large-Scale Web Development with API HardeningPei Wang, Julian Bangert, Christoph KernICSE 2021 · 9 citations
- Enhancing REST API Testing with NLP TechniquesMyeongsoo Kim, Davide Corradini, Saurabh Sinha, Alessandro Orso et al.ISSTA 2023 · 34 citations
- Automated Attack Synthesis by Extracting Finite State Machines from Protocol Specification DocumentsMaria Leonor Pacheco, Max von Hippel, Ben Weintraub, Dan Goldwasser et al.S&P 2022 · 58 citations
