CCR: Towards a Common, Quality-Gated CACAO Integrations Registry for European Cybersecurity Automation

📅 2026-09-23
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
该研究解决了标准化网络安全剧本缺乏产品特定集成的问题,通过创建一个质量控制的CACAO连接器注册表CCR,并开发了一个混合OpenAPI-to-CACAO转换流程来初始化CCR。
📝 Abstract
Standardised, machine-readable cybersecurity playbooks provide a basis for portable, shareable, and reusable incident-response logic. OASIS CACAO provides a vendor-neutral representation for such playbooks, but not the product-specific integration artefacts needed to invoke external products and services. We introduce the Common CACAO Registry (CCR), an open, provenance-aware registry of CACAO HTTP-API connector envelopes. Each envelope captures an API operation's command, inputs, target, authentication-related information, provenance, validation evidence, and maturity metadata. CCR is \emph{quality-gated}, with acceptance requiring both CACAO v2 schema validity and a mean back-validation score of at least 0.8 against the source OpenAPI operation, while a six-level maturity model records progressively stronger evidence and distinguishes gate acceptance from operational readiness. To seed CCR, we develop a hybrid OpenAPI-to-CACAO pipeline. Deterministic code extracts source-derived interface facts, generates identifiers, wires cross-references, and validates structure, while a constrained LLM provides bounded semantic enrichment, including action naming, authentication interpretation, and CACAO activity annotation. Evaluation across eight security APIs yields 713 CACAO-schema-valid envelopes with a mean back-validation score of 91.5\%, of which 675 produce well-formed, dispatchable HTTP requests in a local harness. Comparison with a deterministic rule-based baseline shows that mechanical API structure is preserved more reliably through rule-based translation, while the LLM contributes bounded semantic enrichment, most notably CACAO activity annotation. Together, these results support CCR as reusable integration infrastructure for CACAO action steps and as an initial foundation for a broader common European registry.
Problem

Research questions and friction points this paper is trying to address.

Cybersecurity Playbooks
CACAO
Integration Artifacts
API Connectors
Registry
Innovation

Methods, ideas, or system contributions that make the work stand out.

Common CACAO Registry
Quality-Gated
OpenAPI-to-CACAO Pipeline
Semantic Enrichment
🔎 Similar Papers
No similar papers found.