ESASCF: Expertise Extraction, Generalization and Reply Framework for an Optimized Automation of Network Security Compliance
Mohamed C. Ghanem, Thomas M. Chen, Mohamed A. Ferrag, Mohyi, E. Kettouche

TL;DR
This paper introduces ESASCF, an automated framework that enhances network security compliance testing by automating expertise extraction and re-use, significantly reducing testing time and improving accuracy.
Contribution
The paper presents a novel expert-system framework that automates security compliance assessments, improving efficiency and consistency over traditional manual methods.
Findings
Reduces expert testing time by up to 50%
Improves testing effectiveness and coverage
Enables knowledge reuse for consistent compliance assessments
Abstract
The Cyber threats exposure has created worldwide pressure on organizations to comply with cyber security standards and policies for protecting their digital assets. Vulnerability assessment (VA) and Penetration Testing (PT) are widely adopted Security Compliance (SC) methods to identify security gaps and anticipate security breaches. In the computer networks context and despite the use of autonomous tools and systems, security compliance remains highly repetitive and resources consuming. In this paper, we proposed a novel method to tackle the ever-growing problem of efficiency and effectiveness in network infrastructures security auditing by formally introducing, designing, and developing an Expert-System Automated Security Compliance Framework (ESASCF) that enables industrial and open-source VA and PT tools and systems to extract, process, store and re-use the expertise in a…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Software Engineering Research · Network Security and Intrusion Detection
