Shiggii's picture
Update README.md
d0dc74f verified
|
Raw
History Blame Contribute Delete
5.18 kB
metadata
title: CloudGuard S3 Auditor
emoji: πŸ›‘οΈ
colorFrom: blue
colorTo: gray
sdk: docker
pinned: false
app_port: 7860

πŸ›‘οΈ CloudGuard-S3-Auditor (OpenEnv)

πŸ“Œ Project Overview

CloudGuard-S3-Auditor is a specialized simulation environment for AI agents built on the OpenEnv framework. It simulates the high-stakes role of a Cloud Security Auditor managing S3 storage infrastructure.

The Core Conflict: Security vs. Availability

The primary challenge for an agent in this environment is balancing Security Compliance with Business Continuity.

  • Security Goal: Identify and secure PII (Personally Identifiable Information) and ensure data is encrypted.
  • Business Goal: Ensure "Website Assets" (CSS, Images, etc.) remain public to prevent production outages.

πŸ› οΈ Action & Observation Spaces

Observation Space

The agent receives a list of buckets with real-time metadata:

  • name: Unique bucket identifier.
  • policy: Current access level (public or private).
  • contains_pii: Flag indicating if sensitive data is present.
  • is_required_public: Flag indicating if the bucket is a critical production asset.
  • encryption: Current encryption status (none or aes256).

Action Space

  • make_private:{bucket_name}: Revokes public access.
  • enable_encryption:{bucket_name}:aes256: Applies server-side encryption.

🎯 Tasks & Difficulty Levels

  • Critical Leak (Easy): A single high-risk PII leak must be plugged immediately.
  • Audit & Protect (Medium): 10 mixed buckets. Requires triaging between sensitive data and production assets.
  • Compliance Sweep (Hard): 20 buckets. Full infrastructure hardening without causing a single minute of website downtime.

πŸ“ˆ Reward Function

The environment uses a weighted reward signal:

  • +0.20: Successfully securing a PII-containing bucket or encrypting data.
  • +0.60: Bonus for completing the entire task goal (Terminal Reward).
  • -1.00: Critical failure (Making a required public asset private).

πŸš€ Setup & Local Usage

  1. Install dependencies:
    pip install requests
    
  2. Run the baseline:
    python inference.py
    

πŸ“Š Baseline Performance Results

Model: Rule-Based Logic (OpenEnv-S3-Baseline)
Status: 100% Success Rate (Score 1.0)

πŸš€ Running Final CloudGuard Baseline...

[START] task=critical_leak env=CloudGuard-S3-Auditor model=rule-based-baseline
[STEP]  step=1 action=make_private:customer-pii reward=0.20 done=false error=null
[STEP]  step=2 action=enable_encryption:customer-pii:aes256 reward=0.60 done=true error=null
[END]   success=true steps=2 score=1.0000 rewards=0.20,0.60
--------------------------------------------------
[START] task=audit_and_protect env=CloudGuard-S3-Auditor model=rule-based-baseline
[STEP]  step=1 action=make_private:health-data reward=0.20 done=false error=null
[STEP]  step=2 action=enable_encryption:health-data:aes256 reward=0.20 done=false error=null
[STEP]  step=3 action=make_private:employee-ssn reward=0.20 done=false error=null
[STEP]  step=4 action=enable_encryption:employee-ssn:aes256 reward=0.20 done=false error=null
[STEP]  step=5 action=make_private:user-records reward=0.20 done=false error=null
[STEP]  step=6 action=enable_encryption:user-records:aes256 reward=0.60 done=true error=null
[END]   success=true steps=6 score=1.0000 rewards=0.20,0.20,0.20,0.20,0.20,0.60
--------------------------------------------------
[START] task=compliance_sweep env=CloudGuard-S3-Auditor model=rule-based-baseline
[STEP]  step=1 action=enable_encryption:staging-dump:aes256 reward=0.20 done=false error=null
[STEP]  step=2 action=enable_encryption:config-snapshots:aes256 reward=0.20 done=false error=null
[STEP]  step=3 action=make_private:health-data reward=0.20 done=false error=null
[STEP]  step=4 action=enable_encryption:health-data:aes256 reward=0.20 done=false error=null
[STEP]  step=5 action=enable_encryption:internal-docs:aes256 reward=0.20 done=false error=null
[STEP]  step=6 action=enable_encryption:ml-training-data:aes256 reward=0.20 done=false error=null
[STEP]  step=7 action=make_private:user-records reward=0.20 done=false error=null
[STEP]  step=8 action=enable_encryption:user-records:aes256 reward=0.20 done=false error=null
[STEP]  step=9 action=enable_encryption:analytics-raw:aes256 reward=0.20 done=false error=null
[STEP]  step=10 action=make_private:passport-scans reward=0.20 done=false error=null
[STEP]  step=11 action=enable_encryption:passport-scans:aes256 reward=0.20 done=false error=null
[STEP]  step=12 action=make_private:payment-cards reward=0.20 done=false error=null
[STEP]  step=13 action=enable_encryption:payment-cards:aes256 reward=0.20 done=false error=null
[STEP]  step=14 action=make_private:credit-reports reward=0.20 done=false error=null
[STEP]  step=15 action=enable_encryption:credit-reports:aes256 reward=0.20 done=false error=null
[STEP]  step=16 action=enable_encryption:ci-cache:aes256 reward=0.60 done=true error=null
[END]   success=true steps=16 score=1.0000 rewards=0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.20,0.60