发表机构
Peking University; Southeast University; Huawei Technologies Co., Ltd.(北京大学; 东南大学; 华为技术有限公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对事件响应规划的静态工作流和现有LLM智能体的不足,提出端到端智能体规划框架STAIR,在100个Docker网络靶场中实现0.94标准化防御得分,较最强基线提升9.5%。
AI 中文摘要
事件响应规划对于在网络攻击后恢复受损害的软件系统至关重要。常见做法依赖于专家驱动的剧本,这些剧本编码了固定的响应程序,但这些静态工作流难以适应不断变化的事件状态、变化的恢复目标以及执行反馈。最近基于大语言模型(LLM)的规划器和使用工具的智能体提高了自动化程度,但它们在长周期响应中仍然不稳定,因为它们缺乏维护事件状态、使行动与当前恢复阶段对齐以及复用历史经验的统一基础。我们提出了STAIR,一种用于事件响应的端到端智能体规划框架。该框架将当前事件维护为状态图(Graph-as-State),使用阶段路由器(Stage Router)将规划分配给阶段专用智能体,并检索历史经验以指导行动选择。执行工具(Execution Harness)执行行动、返回反馈以更新事件状态,并验证行动效果以用于未来经验复用。在100个基于Docker的网络靶场中,我们的框架实现了0.94的标准化防御得分,比最强基线提高了9.5%。
英文摘要
Incident response planning is critical for restoring compromised software systems after cyberattacks. Common practice relies on expert-driven playbooks that encode fixed response procedures, but these static workflows struggle to adapt to evolving incident states, changing recovery objectives, and execution feedback. Recent LLM-based planners and tool-using agents improve automation, yet they remain unstable in long-horizon response because they lack a unified basis for maintaining incident state, aligning actions with the current recovery stage, and reusing historical experience. We present STAIR, an end-to-end agentic planning framework for incident response. The framework maintains the current incident as Graph-as-State, uses a Stage Router to dispatch planning to stage-specialized agents, and retrieves historical experiences to guide action selection. An Execution Harness executes actions, returns feedback to update the incident state, and validates action effects for future experience reuse. Across 100 Docker-based cyber ranges, our framework achieves a normalized defense score of 0.94 and improves over the strongest baseline by 9.5%.
Comments12 pages, 5 figures