Hoffmann, MarioBuchmann, Erik2024-08-212024-08-212024https://dl.gi.de/handle/20.500.12116/44283Due to the self-governing, heterogeneous structure, the enforcement of IT-security policies at universities is different from that in business and industry. Fast pacing positional changes and limited IT knowledge result in lost information of systems, configurations and responsibilities. Different needs of the research groups require locally managed IT systems that are not under control of the IT department. In this paper, we describe ChatSEC our approach to help local system admins to close security vulnerabilities. ChatSEC improves vulnerability reports generated by a security appliance. In particular, we utilize AI to intuitively explain vulnerability reports. We also integrate the threat intelligence and mitigation steps needed to understand and close the vulnerabilities. The focus of this paper is on implementation options. Our preliminary findings are essentially positive: Key components can be readily implemented, and have the potential to greatly support local system administrators.enhttp://purl.org/eprint/accessRights/RestrictedAccessChatSEC - Towards Enhancing Security Vulnerability Reports for Non-ExpertsText/Workshop Paper10.18420/muc2024-mci-ws13-144