Conceptio › Archive › arXiv CS
arXiv CSopen access

A Unified Compliance Aggregator Framework for Automated Multi-Tool Security Assessment of Linux Systems

2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

A Unified Compliance Aggregator Framework for Automated Multi-Tool Security Assessment of Linux Systems

arXiv:2604.17256v1 [cs.CR] 19 Apr 2026

Sheldon Paul Department of Computing, Engineering and Mathematical Science Texas A&M University - San Antonio, TX, USA [email protected] Izzat Alsmadi Professor, Department of Computing, Engineering and Mathematical Science Texas A&M University - San Antonio, TX, USA [email protected]

Abstract Assessing the security posture of modern computing systems typically requires the use of multiple specialized tools. These tools focus on different aspects such as configuration compliance, file integrity, and vulnerability exposure, and their outputs are often difficult to interpret collectively. This paper introduces the Unified Compliance Aggregator (UCA), a framework that integrates several open-source security tools into a single composite score representing overall system security. The proposed framework combines outputs from Lynis, OpenSCAP (STIG and CIS profiles), AIDE, Tripwire, and Nmap NSE. A normalization process converts heterogeneous outputs into a consistent 0–100 scale, followed by weighted aggregation. We also introduce a logarithmic scoring model for file integrity measurements to address limitations observed in prior linear approaches. Experiments were conducted on Ubuntu 22.04 across different hardening levels and environments. Results show consistent improvement in composite scores as systems are hardened, while also revealing contrasting behavior between compliance and file integrity tools. Two case studies—a basic web server and a DVWA-based system—illustrate how the framework can be applied in practical scenarios.

Keywords: security auditing, compliance aggregation, system hardening, Linux security, CIS benchmarks, file integrity monitoring, vulnerability scanning, FABRIC testbed, DVWA

1

Introduction

Security assessments are typically performed using multiple independent tools, each targeting a specific domain such as system configuration, vulnerability scanning, or file integrity monitoring. While each tool provides useful information, their outputs are fragmented and often difficult to interpret together. For example, a system administrator may rely on Lynis for configuration auditing, OpenSCAP for compliance checking, and AIDE or Tripwire for file integrity monitoring. Each tool produces its own metrics, formats, and scales, making it challenging to form a unified understanding of the system’s overall security posture. This fragmentation motivates the need for a unified framework that can integrate outputs from multiple tools and provide a consolidated, interpretable measure of security. Standards such as PCI DSS, HIPAA, FedRAMP, and SOC 2 impose requirements spanning configuration management, access control, and vulnerability management simultaneously. No 1

single tool covers all domains. The research objective is to develop a framework that aggregates outputs from multiple security tools, normalizes results to a common scale, and produces a single actionable score reflecting the overall security posture of particularly for Linux operating systems.

1.1

Research Questions

RQ1: How can multiple security tools with different output formats be integrated into a unified framework? RQ2: What normalization methodologies convert diverse outputs into comparable scores? RQ3: How should weighted scoring account for differences in tools scope? RQ4: How does progressive hardening affect the composite score across multiple dimensions? RQ5: What is the practical impact when applied to web server and web application server deployments?

1.2

Contributions

Our previous work [4] introduced UCA using three tools (Lynis, OpenSCAP, AIDE) on FABRIC ([5]), achieving statistically significant results across 108 audit runs. Three limitations remained: no vulnerability assessment, single platform only, and a linear AIDE formula that collapsed beyond 20 file changes. This paper contributes: (1) extended tool integration from three to six; (2) firewall activation identified as the single largest improvement at +47 points; (3) cross-platform validation across VMware and FABRIC; (4) logarithmic AIDE scoring preventing collapse; (5) a basic web server case study (+8.4%); (6) a DVWA web application server case study (+3.8%) using a recognized intentionally vulnerable platform; and (7) empirical evidence that compliance and file integrity tools exhibit opposite trends during hardening.

2

Related Work

2.1

Security Auditing Tools

Lynis [6] performs comprehensive system audits across 300+ tests producing a Hardening Index (0-100). OpenSCAP [8] implements SCAP [7], supporting DISA STIG and CIS profiles through the SCAP Security Guide [9]. CIS Benchmarks [12] provide industry-consensus configurations referenced by PCI DSS, HIPAA, and FedRAMP. AIDE [10] and Tripwire [11] provide file integrity monitoring mandated by PCI DSS Requirement 11.5 and NIST SP 800-53 SI-7 [1]. Nmap [13] with NSE scripts provides network vulnerability detection; OpenVAS [14] offers CVSS-based enterprise scanning.

2.2

Web Application Security and DVWA

Web applications introduce risks cataloged by the OWASP Top 10 [15]. DVWA (Damn Vulnerable Web Application) [16], endorsed by OWASP with 8,000+ GitHub stars, provides a controlled environment with documented SQL injection, XSS, command injection, file inclusion, file upload, CSRF, and brute force vulnerabilities. Used in CEH and OSCP certification courses and university curricula worldwide, it is a credible reproducible research target.

2

2.3

Integration Approaches

SIEM systems [17] aggregate events for monitoring but do not produce compliance scores. SOAR platforms [18] automate incident response without composite metrics. Enterprise platforms (Tenable.io, Qualys VMDR) offer integration but are proprietary [21]. Academic work has explored multi-criteria assessment [19] and automated compliance checking [20]. While their are tools and research publications that focus on the integration of several tools or frameworks to combine the strength of all those tools, we believe that their is still a great value of evaluating the integration of several security tools and evaluate the overall value of such integration. Limited open-source, reproducible frameworks that unify heterogeneous tool outputs into a normalized composite score with empirical validation.

3

Methodology

3.1

Framework Architecture

The UCA framework operates through four phases: (1) tool deployment and database initialization before hardening; (2) scan execution through CLI interfaces; (3) output normalization to 0-100; and (4) weighted aggregation into a composite score. Figure 1 illustrates the architecture. Its important to acknowledge some facts and limitations about UCA. UCA is not a definitive measure of security but a comparative and operational metric.

Figure 1: UCA Framework Architecture. Six tools independently scan the target, outputs are normalized to 0-100, and aggregated through weighted summation into a composite UCA score.

3.2

Tool Selection

Six tools were selected based on open-source availability, Ubuntu support, quantifiable output, complementary domain coverage, and active maintenance (Table 1). Two file integrity tools provide redundant cross-validation; two OpenSCAP profiles provide simultaneous STIG (43 rules) and CIS Level 1 Server (247 rules) coverage. 3

Table 1: UCA Tool Suite

3.3

Tool

Ver.

Domain

Output

Lynis OpenSCAP Std AIDE Tripwire OpenSCAP CIS nmap NSE

3.0.7 1.2.17 0.17.4 2.4.3.7 1.2.17 7.80

System audit STIG compliance File integrity File integrity CIS benchmarks Vulnerability

Index (0-100) Pass/Fail counts Change counts Object/Violation counts Pass/Fail counts CVE/Port findings

Score Normalization

Lynis: SLynis = HardeningIndex, directly extracted (0-100). OpenSCAP (Standard and CIS): SSCAP =

Ppass × 100 Ppass + Pf ail

(1)

AIDE Logarithmic Scoring: The previous linear formula (S = 100−5V ) collapsed beyond 20 changes. The logarithmic replacement maintains sensitivity across hundreds of legitimate hardening-induced modifications: SAIDE = max(0, 100 − 10 · log10 (Vtotal ))

(2)

Tripwire: ST W =

Ototal − Vtotal × 100 Ototal

(3)

Vulnerability Scan: SV uln = max(0, 100 −

P

i wi ni − Pports − Pvulns )

(4)

Severity weights: critical (w=15), high (w=8), medium (w=4), low (w=1); open port penalty 3 per port; confirmed vulnerability penalty 10 each; active firewall reduces total penalty by 10.

3.4

Weighted Aggregation U CA =

6 X

wi · S i ,

X

wi = 1.00

(5)

i=1

Multi-domain tools receive weight 0.20; single-domain tools receive 0.15 (Table 2, Figure 2). We acknowledge that such weights can be subjective and may require further investigations. As an alternative, they can be mapped to CVSS base scores.

3.5

Hardening Specifications

Three progressive hardening levels were defined (Table 3).

3.6

File Integrity Methodology

AIDE and Tripwire databases are initialized once on the unmodified baseline before any hardening and never reinitialized. As hardening progresses, detected file changes increase and integrity scores decrease, the consistent and expected behavior. The weighted UCA formula accounts for this inverse relationship in the composite score. 4

Table 2: UCA Weight Configuration Tool

Weight

Lynis

0.20

OpenSCAP Standard AIDE Tripwire OpenSCAP CIS

0.15 0.15 0.15 0.20

Vulnerability

0.15

Total

1.00

Rationale Multi-domain: 300+ tests across auth, networking, kernel, services Single-focus: STIG (43 rules) Single-domain: file integrity Single-domain: file integrity Multi-domain: CIS Level 1 Server (247 rules) Single-domain: network exposure

Figure 2: UCA weight distribution. Multi-domain tools (Lynis, OpenSCAP CIS) receive 0.20 each; single-domain tools receive 0.15, reflecting scope-based assignment.

4

Experimental Setup

4.1

FABRIC Testbed

Experiments were conducted on the FABRIC research testbed [5], a national-scale programmable infrastructure. The FIU site was used, one of several geographically distributed FABRIC infrastructure locations, analogous to the EDUKY site used in our previous work [4]. Five nodes were provisioned on a private Layer 2 bridge network (10.10.1.0/24). All nodes run Ubuntu 22.04 LTS. The DVWA node was added to the existing slice for Experiment 3. OpenVAS GVM 21.4 was initially planned but exhibited persistent CLI socket errors; nmap 7.80 with NSE scripts was adopted permanently.

4.2

Local VM and Cross-Platform Configuration

Cross-platform validation used VMware Workstation with Ubuntu 22.04.5 LTS (2 cores, 4 GB RAM, 50 GB) using snapshots at each hardening stage. AIDE scans required 30-45 minutes on the 4 GB local VM but completed in approximately 5 minutes on the 8 GB FABRIC nodes.

5

Table 3: Hardening Level Specifications Level

Configuration

Baseline

Default Ubuntu 22.04 LTS, no modifications

Partial

SSH: root login disabled, password auth disabled, MaxAuthTries 3, ClientAlive 300s/2. UFW: deny incoming, allow SSH. CUPS and Avahi disabled. Login banners on /etc/issue, /etc/issue.net

Full

All partial plus: sysctl hardening (IP forwarding off, SYN cookies, ASLR max, SUID dump off, ICMP redirects blocked, reverse path filtering, martian logging). auditd rules for /etc/passwd, /etc/shadow, /etc/group, /etc/sudoers. USB blacklisted. Password aging 90/7/14 days, UMASK 027. Core dumps disabled. Filesystems blacklisted: cramfs, freevxfs, jffs2, hfs, hfsplus, squashfs, udf. SSH: X11/TCP forwarding off, LoginGraceTime 60s, MaxStartups 10:30:60. Banners on /etc/issue, /etc/issue.net, /etc/motd Table 4: FABRIC Node Specifications

4.3

Node

IP

Resources

Role

Baseline Partial Full Scanner DVWA

10.10.1.1 10.10.1.2 10.10.1.3 10.10.1.100 10.10.1.4

4c/8GB/30GB 4c/8GB/30GB 4c/8GB/30GB 4c/8GB/40GB 4c/8GB/30GB

Unhardened control SSH + Firewall Comprehensive Vuln scanner Web app case study

Datasets and Resources

Table 6 summarizes external data dependencies. SCAP content was ComplianceAsCode v0.1.72 (ssg-ubuntu2204-ds.xml, 14 MB SCAP 1.3 DataStream), downloaded from GitHub as it was unavailable in Ubuntu package repositories on FABRIC. Two profiles were used: Standard (43 rules from DISA STIG) and CIS Level 1 Server (247 rules). Vulnerability data utilized NVD through nmap NSE scripts. Hardening configurations derived from CIS Benchmarks, DISA STIGs, NIST SP 800-53, and OWASP guidelines.

5

Results and Analysis

5.1

Progressive Hardening Results

Table 7 presents complete six-tool results across all hardening levels. 5.1.1

Compliance Tools

Lynis rose from 59 to 66 (+11.9%) reflecting SSH, firewall, kernel, and auditd hardening. OpenSCAP Standard improved from 67.4% (29/43) to 77.3% (34/43), +14.7%. OpenSCAP CIS showed the strongest gain from 57.8% (137/237) to 67.1% (163/243), +16.1%, with 26 additional rules satisfied through kernel and filesystem restrictions.

6

Figure 3: FABRIC testbed topology. Five nodes on a private L2 bridge (10.10.1.0/24): three hardening targets, one scanner, and one DVWA node for the web application case study. 5.1.2

File Integrity Tools

The logarithmic formula limited the AIDE score decrease to 8.4 points despite a sevenfold violation increase from baseline to full hardening. Tripwire scanned 76,000+ objects reporting 13,459 violations at baseline (82.4%) increasing to 17,540 after full hardening (77.7%). Agreement between both tools cross-validates the change detection findings. 5.1.3

Vulnerability Assessment

The baseline scored 0 with 2 open ports, no firewall, and 4 confirmed vulnerabilities. Partial hardening activated UFW, filtering 65,534 ports and eliminating all confirmed vulnerabilities. The score plateaued because remaining CVEs (OpenSSH 8.9p1: CVE-2023-38408, CVE-20246387) require software upgrades rather than configuration changes.

5.2

UCA Composite Analysis

The +9.83 point total improvement decomposes as: vulnerability +7.05 pts (71.7%), CIS +1.86 pts, Standard +1.49 pts, Lynis +1.40 pts, Tripwire −0.71 pts, AIDE −1.26 pts. Firewall activation alone accounted for nearly three-quarters of the total improvement.

7

Table 5: Cross-Platform Configuration Comparison Parameter

Local VM

FABRIC

OS CPU / RAM Strategy Network

Ubuntu 22.04.5 2 cores / 4 GB Snapshots Localhost

Ubuntu 22.04 4 cores / 8 GB per node 5 independent VMs L2 Bridge (10.10.1.0/24)

Table 6: External Data Dependencies

5.3

Category

Source

Purpose

SCAP Content

ComplianceAsCode v0.1.72

CIS Benchmarks CVE Data OS Infrastructure Standards

Center for Internet Security NVD / NIST Ubuntu 22.04 LTS FABRIC Testbed [5] CIS, DISA, NIST, OWASP

OpenSCAP compliance evaluation Industry security baselines Vulnerability identification Target system Experimental platform Hardening configuration guidance

Multi-Dimensional Behavior

The divergent tool behavior validates multi-tool aggregation. An organization using only Lynis concludes hardening is working; using only AIDE suggests instability. Only aggregation reveals the complete picture: genuine security improvement with expected filesystem changes as a consequence.

5.4

Cross-Platform Validation

Absolute scores differ due to platform-specific configurations but both environments exhibit consistent improvement trends, confirming platform-independent methodology.

6

Case Studies

6.1

Case Study 1: Basic Apache Web Server

Apache 2.4.52 was installed on the baseline node (10.10.1.1) with default configuration. Hardening included: ServerTokens Prod, ServerSignature Off, TRACE disabled, security headers (X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, CSP, Referrer-Policy, HSTS), directory listing disabled, autoindex/status modules removed, UFW for SSH/HTTP/HTTPS. UCA improved from 49.36 to 53.53 (+8.4%).

6.2

Case Study 2: DVWA Web Application Server

6.2.1

Target Selection

We selected DVWA to balance reproducibility and system-level access requirements. DVWA [16], endorsed by OWASP with 8,000+ GitHub stars and citations in hundreds of academic papers, was selected. Metasploitable 2/3 were rejected because their legacy OS versions (Ubuntu 8.04/14.04) lack compatible SCAP content. External platforms were rejected because only nmap can scan them remotely. 8

Table 7: FABRIC Testbed:Complete Assessment Results Tool

Baseline

Partial

Full

Change

Lynis OpenSCAP Standard AIDE Tripwire OpenSCAP CIS Vulnerability

59 67.4 83.4 82.4 57.8 0

61 69.8 77.7 78.0 58.6 47

66 77.3 75.0 77.7 67.1 47

+11.9% +14.7% −8.4 pts −4.7 pts +16.1% +47 pts

UCA

58.34

64.80

68.17

+16.8%

Figure 4: Individual tool scores across three hardening levels. Compliance tools trend upward; file integrity tools trend downward reflecting legitimate change detection. 6.2.2

DVWA Vulnerability Profile

DVWA provides documented vulnerabilities configurable at four security levels. This study used level “low” (maximally vulnerable): • SQL Injection and Blind SQL Injection • XSS: reflected, stored, DOM-based • Command Injection; File Inclusion (LFI/RFI) • Unrestricted File Upload; CSRF; Brute Force 6.2.3

Measurement Scope

The UCA framework measures OS-level and network-level security posture. DVWA’s PHP application vulnerabilities (SQLi, XSS, command injection) are invisible to Lynis, OpenSCAP, AIDE, and Tripwire, which assess the Ubuntu 22.04 host configuration. The nmap scan operates at the network layer, detecting open ports, service CVEs, and misconfigurations, including an 9

Table 8: AIDE Detailed Change Detection Level

Added

Removed

Changed

Total

Score

Baseline Partial Full

11 6 129

0 0 0

35 165 188

46 171 317

83.4 77.7 75.0

Table 9: Vulnerability Scan Results Metric Open Ports Firewall Active Filtered Ports Confirmed Vulns Vulnerability Score

Baseline

Partial

Full

2 No 0 4 0

1 Yes 65,534 0 47

1 Yes 65,534 0 47

exposed .git directory confirmed at baseline. This case study evaluates the server hosting DVWA, not the PHP application itself, consistent with the framework’s design scope. 6.2.4

Setup

DVWA was deployed on node 10.10.1.4 (Ubuntu 22.04, 4 cores, 8 GB RAM) with Apache 2.4.52, PHP 8.1.2, and MariaDB 10.6.23, cloned from the official GitHub repository. All six UCA tools were installed. AIDE and Tripwire databases were initialized once before any hardening. 6.2.5

Hardening Applied

SSH: Root login/password auth disabled, MaxAuthTries 3, X11/TCP forwarding disabled. Firewall: UFW deny incoming, allow 22/80/443; reduced open ports from 3 to 2. Kernel: Full sysctl hardening (IP forwarding off, SYN cookies, ASLR max, SUID dump off). System: auditd with web-specific rules; password aging; filesystem blacklist; core dumps disabled. Apache: ServerTokens Prod, ServerSignature Off, TraceEnable Off, security headers, autoindex/status disabled. PHP: expose_php Off, display_errors Off. Remediation: Exposed .git directory removed.

10

Figure 5: UCA composite scores: 58.34 (baseline), 64.80 (partial), 68.17 (full), representing +16.8% total improvement. Table 10: Cross-Platform Score Comparison (Baseline / Partial / Full)

6.2.6

Tool

Local VM

FABRIC

Lynis OpenSCAP Standard OpenSCAP CIS Tripwire

61 / 63 / 68 76.7 / 69.7 / 77.2 64.3 / 60.7 / 68.3 98.7 / 93.3 / 98.3

59 / 61 / 66 67.4 / 69.8 / 77.3 57.8 / 58.6 / 67.1 82.4 / 78.0 / 77.7

Results and Analysis Table 11: Case Study Results Comparison Basic Web Server

DVWA Server

Before

After

Before

After

Lynis OpenSCAP Std AIDE Tripwire OpenSCAP CIS Vulnerability

58 67.4 52.6 55.2 57.4 0

65 77.3 52.6 51.9 66.3 0

60 60.5 84.2 88.6 57.0 81

67 70.5 73.8 72.0 66.3 94

UCA Gain

49.36 53.53 +8.4%

Tool

11

70.55 73.20 +3.8%

Figure 6: Score trends revealing three patterns: compliance tools trending upward, file integrity tools trending downward, and vulnerability scanning showing a step-function improvement at firewall activation.

Figure 7: Grouped bar comparison of individual tool scores and composite UCA scores before and after hardening for both case studies. The DVWA server starts at a higher baseline (70.55 vs 49.36) reflecting Ubuntu 22.04 defaults with a full LAMP stack. Compliance tools improve in both deployments. File integrity tools decline from hardening-induced changes. The vulnerability score improves by 13 points on the DVWA server through firewall activation and .git removal. UCA composite improves +8.4% (basic) and +3.8% (DVWA), consistent with diminishing returns at higher baselines. Compliance improvement: Lynis +7, OpenSCAP Standard +10.0, CIS +9.3 confirm hardening addressed requirements across multiple frameworks simultaneously. File integrity decline: AIDE −10.4 and Tripwire −16.6 correctly detected hardeninginduced filesystem changes. This is expected and consistent with Experiment 1. 12

Vulnerability improvement: Score rose from 81 to 94 (+13 pts) through firewall activation and .git removal. Remaining CVEs require package upgrades beyond configuration scope. Diminishing returns: The DVWA node started at 70.55 because Ubuntu 22.04 with a LAMP stack satisfies many compliance rules by default. The 3.8% net improvement reflects diminishing returns at higher security levels. Individual tool improvements of up to +13 points confirm the framework detects real security gains.

7

Discussion

7.1

Framework Effectiveness

Across all three experiments the UCA framework detected improvements from 3.8% to 16.8% with individual tool changes spanning −16.6 to +47 points. Weighted aggregation correctly balanced opposing trends, producing net positive composites reflecting genuine improvement. The multi-tool approach generated insights unavailable to single-tool assessment: firewall as the dominant driver (71.7%), file integrity cross-validation, and quantified diminishing returns across deployment types.

7.2

Comparison with Previous Work Table 12: Evolution from UCA v1.0 to v2.0 Feature

v1.0 [4]

v2.0

Tools Weights Platform File Integrity Compliance Vulnerability AIDE Scoring UCA Improvement Case Studies

3 0.4/0.4/0.2 FABRIC EDUKY AIDE only Standard only None Linear +25.9% None

6 0.15-0.20 FABRIC FIU + VMware AIDE + Tripwire Standard + CIS nmap NSE Logarithmic +16.8% 2 (web server, DVWA)

The larger v1.0 improvement reflects a lower EDUKY baseline (39.73% vs 67.4% OpenSCAP) and custom rule scoring. V2.0 exchanges statistical depth for broader coverage, vulnerability assessment, cross-platform validation, and practical case studies.

7.3

Principal findings

1. Progressive hardening produced +16.8% UCA improvement (58.34 to 68.17), with compliance tools gaining 11.9-16.1% and file integrity tools correctly detecting changes. 2. Firewall activation contributed +47 vulnerability points (71.7% of total), invisible without vulnerability scanning integration. 3. The logarithmic AIDE formula prevented score collapse across 317 cumulative changes, resolving v1.0’s primary limitation. 4. Cross-platform validation on VMware and FABRIC confirmed platform-independent methodology. 5. The DVWA case study achieved +3.8% net improvement with individual tool gains up to +13 points, demonstrating applicability to web application server environments and confirming diminishing returns at higher baselines. 13

6. Divergent tool behavior provides empirical validation to suggest that no single tool captures the complete security picture. All tools, configurations, and methodologies are open-source and documented for reproduction and extension.

7.4

Limitations and Validity Assessment

OpenVAS unavailability: GVM 21.4 CLI errors required nmap substitution, reducing CVSS granularity. Static weights: Manual assignment; ML-based optimization planned. Version CVEs: OpenSSH 8.9p1 and Apache 2.4.52 CVEs persist post-hardening; require package upgrades. Single distribution: Ubuntu 22.04 only; SCAP content requires adaptation for other distributions. Statistical depth: Single scans per configuration; multiple runs would strengthen claims. OS vs application layer: DVWA’s PHP vulnerabilities are outside UCA scope; application security tool integration would extend coverage. One important limitation in this paper that we acknowledge and can significantly impact the validity of the results is that the experiments were reported after one cycle. Their is a need to execute those experiments several times in different environments to ensure stability of results.

8

Future Work

LLM Integration: Microsoft Phi-3 and Meta Llama 3 can analyze UCA outputs, generate risk explanations, and prioritize remediation by predicted score impact. Adaptive Weighting: Random Forest classifier trained on experimental data to optimize weights per deployment context. Automated Remediation: Scripts generating prioritized remediation commands from UCA output. Statistical Validation: Multiple independent runs with t-tests and effect size calculations. Cross-Distribution and Cloud: CentOS, Debian, Rocky Linux; AWS, Azure, GCP. Continuous Monitoring: Scheduled scans with alerting below defined thresholds. Application-Layer Integration: Dedicated web application security tools extending UCA to OWASP Top 10 scope.

9

Conclusion

This paper presented a unified framework for aggregating outputs from multiple security tools into a single composite score. The framework improves interpretability of security assessments and provides a practical approach for evaluating system hardening. While further validation is needed, the results suggest that multi-tool aggregation can offer useful insights into system security posture.

References [1] NIST, “Security and Privacy Controls for Information Systems and Organizations,” SP 80053 Rev. 5, 2020. [2] IBM Security, “Cost of a Data Breach Report 2023,” IBM Corporation, 2023. [3] Verizon, “2023 Data Breach Investigations Report,” Verizon Enterprise Solutions, 2023. [4] S. Paul and I. Alsmadi, “Security Hardening Using FABRIC: Implementing a Unified Compliance Aggregator,” arXiv:2601.00909, 2025. 14

[5] I. Baldin et al., “FABRIC: A National-Scale Programmable Experimental Network Infrastructure,” IEEE Internet Computing, vol. 23, no. 6, pp. 38-47, 2019. [6] CISOfy, “Lynis Security Auditing Tool,” https://cisofy.com/lynis/ [7] D. Waltermire et al., “Technical Specification for SCAP,” NIST SP 800-126 Rev. 3, 2018. [8] OpenSCAP Project, “OpenSCAP NIST Certified Toolkit,” https://www.open-scap.org/ [9] ComplianceAsCode, “SCAP Security Guide,” https://github.com/ComplianceAsCode/ content [10] R. Lehti and P. Virolainen, “AIDE,” https://aide.github.io/ [11] Tripwire Inc., “Open tripwire-open-source

Source

[12] Center for Internet Security, cis-benchmarks

Tripwire,”

“CIS Benchmarks,”

https://github.com/Tripwire/ https://www.cisecurity.org/

[13] G. Lyon, Nmap Network Scanning, Nmap Project, 2009. [14] Greenbone Networks, “OpenVAS,” https://www.openvas.org/ [15] OWASP Foundation, “OWASP Top Ten,” https://owasp.org/Top10/ [16] DVWA Project, “Damn Vulnerable Web Application,” https://github.com/digininja/ DVWA [17] A. Chuvakin, K. Schmidt, and C. Phillips, Logging and Log Management, Syngress, 2012. [18] Gartner, “Market Guide for SOAR Solutions,” 2019. [19] A. Shameli-Sendi et al., “Taxonomy of ISRA,” Computers & Security, vol. 57, pp. 14-30, 2016. [20] M. Schwartz et al., “Automated Security Compliance Assessment,” Bell Labs Technical Journal, vol. 12, no. 3, pp. 203-218, 2007. [21] A. Alhomoud et al., “A Survey on Vulnerability Assessment Tools,” ICICS, pp. 1–6, 2011.

15

Record · ID 120439 · SHA-256 072ce8649fe9b5a9
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.