arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

(EC)2:基于多智能体大语言模型调查的网络安全以事件为中心的可解释性

(EC)2: Event-Centric Explainability for Cybersecurity Through Multi-Agent LLM Investigations

Neta Kirmayer, David Tayouri, Andrés Murillo, Motoyoshi Sekiya, Asaf Shabtai, Rami Puzis

arXiv 2607.26201首次发表:更新:

发表机构

Ben-Gurion University of the Negev; Fujitsu(内盖夫本-古里安大学; 富士通)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究提出多智能体框架(EC)2,为中小型企业网络的网络安全警报提供基于可验证证据的以事件为中心的可解释性,可提升检测后分析效果与事件分类准确率。

AI 中文摘要

安全运营中心依赖异常检测系统标记可疑事件,异常检测器的特征级解释对运营调查价值有限。分析师需了解实体间的上下文关系并获得可操作的理解,才能有效处理警报。本文提出一种适用于中小型企业网络的、与检测器无关的以事件为中心的网络安全警报解释方法,介绍了多智能体框架(EC)2,该框架开展结构化、假设驱动的调查,提供基于可验证证据的解释。评估结果显示,该框架生成具有操作意义的解释,提升了检测后分析效果,还提高了事件分类准确率。

英文摘要

Security operations centers rely on anomaly detection systems to flag suspicious events. Feature-level explanations for anomaly detectors offer limited value for operational investigations. To effectively handle alerts, analysts need to know contextual relationships and need actionable understanding of the entities involved. This paper introduces an event-centric detector-agnostic approach for explaining cybersecurity alerts in small- to medium-sized enterprise networks. We present (EC)2, a multi-agent framework that performs structured, hypothesis-driven investigation to provide explanations grounded in verifiable evidence. Evaluation results show that the proposed framework improves post-detection analysis by generating operationally meaningful explanations, which also enhance event classification accuracy.

Comments21 pages

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑