AspisAI: A Canonical, Machine-Interpretable Governance Framework for Automated Multi-Standard Compliance Monitoring
本文提出AspisAI框架,通过将多种标准要求转化为机器可解释的模型并评估证据,解决多标准合规监测成本高、一致性差的问题。
本文提出AspisAI框架,通过将多种标准要求转化为机器可解释的模型并评估证据,解决多标准合规监测成本高、一致性差的问题。
本文重新评估了FIDO2威胁模型,通过分析八种攻击向量展示了其在实际部署中的安全假设可能不成立,并指出需采取多层次缓解措施以保障安全。
本文通过构建一个包含67,502次扫描的多层活跃网络原始证据数据集,解决了现有钓鱼网站研究中因仅使用URL或预计算特征而丢失底层证据的问题。
This study addresses critical vulnerabilities in SSH password authentication, including susceptibility to slow brute-force attacks, credential spraying, and phishing or session hijacking exploits targeting conventional account recovery mechanisms. To counter these threats, the authors propose a real-time detection and response framework based on time-series log analysis. By employing multi-scale sliding windows to extract behavioral features and integrating a lightweight LightGBM classifier, the system achieves 99.96% attack detection accuracy within 10 seconds and automatically locks compromised accounts. Furthermore, the work introduces a novel credential rotation protocol that eliminates reliance on sessions, email, or one-time passwords (OTPs), instead leveraging single-use cryptographic binding and passkey-based authentication to enable secure and efficient password resets, thereby significantly enhancing resilience against a broad spectrum of cyberattacks.
This work proposes a read-only file security sharing architecture based on Selective Disclosure JWT (SD-JWT), addressing limitations of traditional identity and access management (IAM) systems—such as complex configuration, security vulnerabilities, and the absence of a unified cross-format digital signature mechanism. By embedding digitally signed, integrity-protected metadata directly within files, the approach enables decentralized, verifiable authenticity at the file level without relying on centralized authentication or user databases. This is the first application of SD-JWT to file-level secure sharing, offering strong security guarantees for immutable resources while supporting cross-format distribution and significantly simplifying deployment.
本文提出AspisAI框架,通过将多种标准要求转化为机器可解释的模型并评估证据,解决多标准合规监测成本高、一致性差的问题。
本文重新评估了FIDO2威胁模型,通过分析八种攻击向量展示了其在实际部署中的安全假设可能不成立,并指出需采取多层次缓解措施以保障安全。
本文通过构建一个包含67,502次扫描的多层活跃网络原始证据数据集,解决了现有钓鱼网站研究中因仅使用URL或预计算特征而丢失底层证据的问题。
This study addresses critical vulnerabilities in SSH password authentication, including susceptibility to slow brute-force attacks, credential spraying, and phishing or session hijacking exploits targeting conventional account recovery mechanisms. To counter these threats, the authors propose a real-time detection and response framework based on time-series log analysis. By employing multi-scale sliding windows to extract behavioral features and integrating a lightweight LightGBM classifier, the system achieves 99.96% attack detection accuracy within 10 seconds and automatically locks compromised accounts. Furthermore, the work introduces a novel credential rotation protocol that eliminates reliance on sessions, email, or one-time passwords (OTPs), instead leveraging single-use cryptographic binding and passkey-based authentication to enable secure and efficient password resets, thereby significantly enhancing resilience against a broad spectrum of cyberattacks.
This work proposes a read-only file security sharing architecture based on Selective Disclosure JWT (SD-JWT), addressing limitations of traditional identity and access management (IAM) systems—such as complex configuration, security vulnerabilities, and the absence of a unified cross-format digital signature mechanism. By embedding digitally signed, integrity-protected metadata directly within files, the approach enables decentralized, verifiable authenticity at the file level without relying on centralized authentication or user databases. This is the first application of SD-JWT to file-level secure sharing, offering strong security guarantees for immutable resources while supporting cross-format distribution and significantly simplifying deployment.