arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

智能云诱饵:一种用于自主入侵调查的欺骗驱动框架

Agentic Cloud Decoys: A Deception-Driven Framework for Autonomous Intrusion Investigation

Mohan Manivannan, Dalal Alharthi

arXiv 2607.24006首次发表:更新:

发表机构

College of Information Science University of Arizona Tucson, AZ, USA

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究针对云遥测使入侵理解困难的问题,提出云诱饵人工智能代理框架,通过会话聚合运算符、动态提示生成等方法,在十个AWS S3场景测试中效果良好,能压缩调查路径,多数场景可完全重建,且延迟短。

AI 中文摘要

云遥测数据规模庞大,反而使入侵理解变得更加困难。攻击者通过合法身份、联合会话令牌和与常规管理无异的云原生API进行操作,分析师需花费时间重建日志中已包含的上下文。我们提出了云诱饵人工智能代理,这是一个将高保真云诱饵与自主语言模型代理相结合的框架,可压缩从可疑活动到分析师可用报告的路径。连接诱饵和代理并非易事。调查单位是会话而非事件,联合凭证引入的身份分层会掩盖会话密钥。代理的证据范围必须受限,因为可自由查询完整控制平面历史记录的代理会继承欺骗本应消除的成本和误报情况。而且云遥测部分由对手编写,因为对象键和用户代理字符串是攻击者选择的值,提供商原封不动地记录下来,这使得任何从日志到提示路径都成为间接提示注入通道,诱饵会扩大而非缩小该通道。我们通过仅从提供商派生字段中提取的枢轴元组上的会话聚合运算符以及动态提示生成来解决前两个问题,动态提示生成是一个两阶段提示组装过程,通过仅携带代理观察到的字段来强制实现基础不变性。我们将第三个问题识别为这类系统中未解决的风险,指定了所需缓解措施,并指出我们的原型未实现此措施。在十个受控的AWS S3场景中,九个被完全重建,没有报告包含无法追溯到观察到的工件的断言,延迟为四到五分钟。我们还说明了此评估未确立的内容,并指出能解决此问题的比较。

英文摘要

Cloud telemetry arrives at a scale that, paradoxically, makes intrusion understanding harder rather than easier. Attackers operate through legitimate identity, federated session tokens, and cloud native APIs indistinguishable from routine administration, and analysts spend an incident reconstructing context the logs already contain. We present Cloud Decoy AI Agent, a framework pairing a high fidelity cloud decoy with an autonomous language model agent that compresses the path from suspicious activity to an analyst ready report. Connecting a decoy to an agent is not a wiring exercise. The unit of investigation is the session rather than the event, and the session key is obscured by the identity layering federated credentials introduce. The agent's evidence horizon must be bounded, since an agent free to query full control plane history inherits the cost and false positive profile deception was meant to remove. And cloud telemetry is partly adversary authored, since object keys and user agent strings are attacker chosen values providers record verbatim, which makes any log to prompt path an indirect prompt injection channel that a decoy widens rather than narrows. We address the first two with a session aggregation operator over a pivot tuple drawn only from provider derived fields, and with dynamic prompt generation, a two stage prompt assembly enforcing a grounding invariant by carrying only fields the agent observed. We identify the third as an unaddressed exposure in this class of system, specify the mitigation it requires, and note our prototype does not implement it. Across ten controlled AWS S3 scenarios, nine were reconstructed completely, no report contained an assertion untraceable to an observed artifact, and latency was four to five minutes. We also state what this evaluation does not establish and name the comparisons that would settle it.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑