Towards Practical Realization of Intent-Based Security Paradigm: Design and Implementation of an LLM-Powered Host-Level Security System

avoin
Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.
Lataukset1

Verkkojulkaisu

DOI

Tiivistelmä

As digital technologies continue to grow, computer applications are becoming an essential part of everyday life. These applications need a host machine to run, whether it is a physical machine or a virtual machine. In existing host machines, security settings are typically configured manually by users, using low-level configurations. This process can be time-consuming and error-prone, and often requires specialized technical knowledge. This can lead to security gaps and make security management difficult. One way to simplify this kind of manual configuration is an intent-based approach, where users describe what they want the system to achieve instead of specifying the low-level implementation details. This approach has already been applied in networking, where users state their network goals and the system works out the configurations needed to meet them. However, the concept is underexplored in the domain of host-level security. This thesis addresses that gap by extending the intent-based approach to host-level security. The study used literature review, case study, requirements engineering, and user journey mapping. Existing intent-based systems were examined to understand their capabilities and limitations. Based on the findings, this thesis proposes an architecture for a system that receives security intent expressed by a user in natural language and fulfills it on a host machine. The proposed architecture interprets the intent using large language models, translates it into executable actions, and executes them on the host machine. The thesis also introduces a unified structure to represent security intent, the steps required to fulfill that intent, and the information needed for intent-lifecycle management in a machine-friendly form. The proposed architecture was validated through both scenario-based and empirical evaluations performed with a proof-of-concept prototype. The validation results suggest that an intent-based approach is a promising solution for simplifying host-level security management. By allowing the user to define security intent in natural language, the proposed architecture makes host-level security management easy for a user without in-depth technical knowledge. This thesis lays the groundwork for further research into more user-friendly ways of managing host-level security.

item.page.okmtext