Enhancing Security Control Production With Generative AI
Chen Ling, Mina Ghashami, Vianne Gao, Ali Torkamani, Ruslan Vaulin,, Nivedita Mangam, Bhavya Jain, Farhan Diwan, Malini SS, Mingrui Cheng, Shreya, Tarur Kumar, Felix Candelario

TL;DR
This paper presents a framework using Generative AI to rapidly generate security controls in Gherkin language, significantly reducing development time and improving efficiency for cloud security management.
Contribution
It introduces a structured approach leveraging large language models and retrieval-augmented generation to automate security control creation in Gherkin code.
Findings
Reduces security control development time from days to under a minute
Demonstrates effective use of GenAI on AWS cloud services
Enhances accuracy and efficiency of security control generation
Abstract
Security controls are mechanisms or policies designed for cloud based services to reduce risk, protect information, and ensure compliance with security regulations. The development of security controls is traditionally a labor-intensive and time-consuming process. This paper explores the use of Generative AI to accelerate the generation of security controls. We specifically focus on generating Gherkin codes which are the domain-specific language used to define the behavior of security controls in a structured and understandable format. By leveraging large language models and in-context learning, we propose a structured framework that reduces the time required for developing security controls from 2-3 days to less than one minute. Our approach integrates detailed task descriptions, step-by-step instructions, and retrieval-augmented generation to enhance the accuracy and efficiency of the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Network Security and Intrusion Detection
MethodsFocus
