Spaces:
Sleeping
Sleeping
metadata
title: CloudGuard S3 Auditor
emoji: π‘οΈ
colorFrom: blue
colorTo: gray
sdk: docker
pinned: false
app_port: 7860
π‘οΈ CloudGuard-S3-Auditor (OpenEnv)
π Project Overview
CloudGuard-S3-Auditor is a specialized simulation environment for AI agents built on the OpenEnv framework. It simulates the high-stakes role of a Cloud Security Auditor managing S3 storage infrastructure.
The Core Conflict: Security vs. Availability
The primary challenge for an agent in this environment is balancing Security Compliance with Business Continuity.
- Security Goal: Identify and secure PII (Personally Identifiable Information) and ensure data is encrypted.
- Business Goal: Ensure "Website Assets" (CSS, Images, etc.) remain public to prevent production outages.
π οΈ Action & Observation Spaces
Observation Space
The agent receives a list of buckets with real-time metadata:
name: Unique bucket identifier.policy: Current access level (publicorprivate).contains_pii: Flag indicating if sensitive data is present.is_required_public: Flag indicating if the bucket is a critical production asset.encryption: Current encryption status (noneoraes256).
Action Space
make_private:{bucket_name}: Revokes public access.enable_encryption:{bucket_name}:aes256: Applies server-side encryption.
π― Tasks & Difficulty Levels
- Critical Leak (Easy): A single high-risk PII leak must be plugged immediately.
- Audit & Protect (Medium): 10 mixed buckets. Requires triaging between sensitive data and production assets.
- Compliance Sweep (Hard): 20 buckets. Full infrastructure hardening without causing a single minute of website downtime.
π Reward Function
The environment uses a weighted reward signal:
- +0.20: Successfully securing a PII-containing bucket or encrypting data.
- +0.60: Bonus for completing the entire task goal (Terminal Reward).
- -1.00: Critical failure (Making a required public asset private).
π Setup & Local Usage
- Install dependencies:
pip install requests - Run the baseline:
python inference.py
π Baseline Performance Results
Model: Rule-Based Logic (OpenEnv-S3-Baseline)
Status: 100% Success Rate (Score 1.0)
π Running Final CloudGuard Baseline...
[START] task=critical_leak env=CloudGuard-S3-Auditor model=rule-based-baseline
[STEP] step=1 action=make_private:customer-pii reward=0.20 done=false error=null
[STEP] step=2 action=enable_encryption:customer-pii:aes256 reward=0.60 done=true error=null
[END] success=true steps=2 score=1.0000 rewards=0.20,0.60
--------------------------------------------------
[START] task=audit_and_protect env=CloudGuard-S3-Auditor model=rule-based-baseline
[STEP] step=1 action=make_private:health-data reward=0.20 done=false error=null
[STEP] step=2 action=enable_encryption:health-data:aes256 reward=0.20 done=false error=null
[STEP] step=3 action=make_private:employee-ssn reward=0.20 done=false error=null
[STEP] step=4 action=enable_encryption:employee-ssn:aes256 reward=0.20 done=false error=null
[STEP] step=5 action=make_private:user-records reward=0.20 done=false error=null
[STEP] step=6 action=enable_encryption:user-records:aes256 reward=0.60 done=true error=null
[END] success=true steps=6 score=1.0000 rewards=0.20,0.20,0.20,0.20,0.20,0.60
--------------------------------------------------
[START] task=compliance_sweep env=CloudGuard-S3-Auditor model=rule-based-baseline
[STEP] step=1 action=enable_encryption:staging-dump:aes256 reward=0.20 done=false error=null
[STEP] step=2 action=enable_encryption:config-snapshots:aes256 reward=0.20 done=false error=null
[STEP] step=3 action=make_private:health-data reward=0.20 done=false error=null
[STEP] step=4 action=enable_encryption:health-data:aes256 reward=0.20 done=false error=null
[STEP] step=5 action=enable_encryption:internal-docs:aes256 reward=0.20 done=false error=null
[STEP] step=6 action=enable_encryption:ml-training-data:aes256 reward=0.20 done=false error=null
[STEP] step=7 action=make_private:user-records reward=0.20 done=false error=null
[STEP] step=8 action=enable_encryption:user-records:aes256 reward=0.20 done=false error=null
[STEP] step=9 action=enable_encryption:analytics-raw:aes256 reward=0.20 done=false error=null
[STEP] step=10 action=make_private:passport-scans reward=0.20 done=false error=null
[STEP] step=11 action=enable_encryption:passport-scans:aes256 reward=0.20 done=false error=null
[STEP] step=12 action=make_private:payment-cards reward=0.20 done=false error=null
[STEP] step=13 action=enable_encryption:payment-cards:aes256 reward=0.20 done=false error=null
[STEP] step=14 action=make_private:credit-reports reward=0.20 done=false error=null
[STEP] step=15 action=enable_encryption:credit-reports:aes256 reward=0.20 done=false error=null
[STEP] step=16 action=enable_encryption:ci-cache:aes256 reward=0.60 done=true error=null
[END] success=true steps=16 score=1.0000 rewards=0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.60