发表机构
City University of Hong Kong; Fordham University(香港城市大学; 福特汉姆大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对网络事件响应效率低的问题,提出整合LLM攻击推理、滚动规划与数字孪生验证的分层智能体响应框架,在33组件企业网络测试台的多阶段攻击场景中,其恢复成功率较前沿LLM基线提升18%-31%。
AI 中文摘要
网络事件响应仍缓慢且劳动密集,防御者必须从部分观测中推断多阶段攻击,并将恢复决策转化为可靠的系统命令。决策论规划器提供了原则性优化,但通常依赖抽象状态和预定义动作;而大语言模型(LLM)智能体可对操作上下文进行推理,但可能会在攻击和响应方面产生幻觉。为实现响应规划的自动化,本文提出一种分层智能体响应框架,该框架整合了基于LLM的攻击推理、滚动规划以及数字孪生验证。一个微调后的LLM从安全警报和系统测量中推断攻击进展与受影响主机;一个仿真网络数字孪生重放推断出的攻击,并返回预测与观测效果之间的差异以校准推理;一个单独微调的规划智能体在战术层使用滚动规划方法对受影响组件进行优先级排序;在操作层,规划智能体提出高级恢复动作,执行智能体则将选定动作转化为恢复和验证命令,并在数字孪生中进行验证。我们在包含33个组件的企业网络测试台上,针对三种多阶段攻击场景对该框架进行评估,结果表明,与前沿LLM基线相比,本框架的恢复成功率高出18%至31%。
英文摘要
Network incident response remains slow and labor-intensive as the defender must infer multi-stage attacks from partial observations and translate recovery decisions into reliable system commands. Decision-theoretic planners provide principled optimization but typically rely on abstract states and predefined actions, while large language model (LLM) agents can reason over operational context but may hallucinate attacks and responses. Toward automating response planning, we present a hierarchical agentic response framework that integrates LLM-based attack inference, rollout planning, and digital-twin validation. A fine-tuned LLM infers the attack progression and affected hosts from security alerts and system measurements. An emulated network digital twin replays the inferred attack and returns discrepancies between predicted and observed effects to calibrate the inference. A separately fine-tuned planning agent uses the rollout planning method to prioritize affected components at the tactical layer. At the operational layer, the planning agent proposes high-level recovery actions, and an execution agent translates selected actions into recovery and verification commands that are validated in the digital twin. We evaluate the framework on a 33-component enterprise-network testbed under three multi-stage attack scenarios. The results show that our framework outperforms frontier-LLM baselines in recovery success rate by 18--31%.
Comments2026 IEEE Conference on Communications and Network Security