| Veröffentlichte Version Download ( PDF | 925kB) | Lizenz: Creative Commons Namensnennung 4.0 International |
Generating semi-automated security playbooks for vulnerability mitigation from unstructured advisory data
Artikel
Oberhofer, Daniel
, Grill, Johannes
, Pernul, Günther
und Schönig, Stefan
(2026)
Generating semi-automated security playbooks for vulnerability mitigation from unstructured advisory data.
International Journal of Information Security 25 (151).
DOI zum Zitieren dieses Dokuments: 10.5283/epub.80597
Zusammenfassung
Automated security risk management addresses threats by implementing mitigation and remediation strategies described in public security advisories. These advisories, regularly published by independent Cyber Emergency Response Teams (CERTs), are typically presented as unstructured text and supplemented with additional security-relevant information sources. Using a Large Language Model (LLM) ...
Automated security risk management addresses threats by implementing mitigation and remediation strategies described in public security advisories. These advisories, regularly published by independent Cyber Emergency Response Teams (CERTs), are typically presented as unstructured text and supplemented with additional security-relevant information sources. Using a Large Language Model (LLM) orchestration framework, we generate security playbooks in a standardized meta-model, visualize them with Business Process Modeling and Notation (BPMN) diagrams, and classify them into actionable tasks. We present the theoretical foundations of the framework, describe the underlying meta-model, and conduct an experimental study that produces a dataset of 725 security playbooks. Our subsequent content analysis shows that advisory-based playbooks focus on update tasks, but also include defensive themes like disabling vulnerable policies or restricting network access.
Alternative Links zum Volltext
Beteiligte Einrichtungen
Details
| Dokumentenart | Artikel | ||||
| Titel eines Journals oder einer Zeitschrift | International Journal of Information Security | ||||
| Verlag | Springer Nature | ||||
| Open Access Art | DEAL (Springer Gold) | ||||
| Band | 25 | ||||
| Nummer des Zeitschriftenheftes oder des Kapitels | 151 | ||||
| Datum | 1 September 2026 | ||||
| Veröffentlichungsdatum | 02 Sep 2026 08:50 | ||||
| Institutionen | Wirtschaftswissenschaften > Institut für Wirtschaftsinformatik > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul) Informatik und Data Science > Fachbereich Wirtschaftsinformatik > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul) Informatik und Data Science > Fachbereich Wirtschaftsinformatik | ||||
| Identifikationsnummer |
| ||||
| Stichwörter / Keywords | Security Advisories · Playbooks · LLM · BPMN · Security Management | ||||
| Dewey-Dezimal-Klassifikation | 000 Informatik, Informationswissenschaft, allgemeine Werke > 004 Informatik | ||||
| Status | Veröffentlicht | ||||
| Begutachtet | Ja, diese Version wurde begutachtet | ||||
| An der Universität Regensburg entstanden | Ja | ||||
| URN der UB Regensburg | urn:nbn:de:bvb:355-epub-805976 | ||||
| Dokumenten-ID | 80597 |
Downloadstatistik
Downloadstatistik