发表机构
University of South Florida; Cyber Florida(南佛罗里达大学; 佛罗里达网络安全中心)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文通过一年多的实地部署,在安全运营中心创建智能体AI伴侣,发现超90%输出被分析师复用,证明与用户共同设计的AI系统能超越工具定位,提升信任与生产力。
AI 中文摘要
安全运营中心(SOC)处理大量工单,其中大多数是低关注度事件,不值得进一步调查。这项任务的重复性以及大量工单的相似性,使其成为基于生成式AI自动化的理想候选场景。我们通过在一家SOC内开展为期一年多的实地工作,利用大语言模型创建并部署了一个智能体AI伴侣。该SOC AI伴侣的设计由研究人员在SOC日常工作中的参与和互动所驱动。在实地工作的最后四个月,SOC分析师受邀使用该伴侣。我们分析了分析师对伴侣的使用情况,发现在超过90%的案例中,伴侣的输出被分析师复用于工单的结案报告中。我们的结果表明,当与预期用户“在战壕中”共同设计时,SOC AI伴侣可以超越“又一款工具”的定位,而成为一个与其人类用户共同演化的系统,因为它遍历各种类型的工作负载。分析师自然而然地开始塑造AI伴侣的行为,以适应他们的特定需求。我们的数据显示,人类分析师对AI伴侣行为的塑造越多,他们就越倾向于信任AI系统输出的结果,从而带来生产力的提升。
英文摘要
Security Operations Centers (SOCs) process large amounts of tickets, most of which are low-interest events not worthy of further investigation. The repetitive nature of this task and similarity of the vast amounts of tickets make it a prime candidate for generative AI-based automation. We created and deployed an agentic AI companion utilizing large language models through fieldwork within a SOC for over one year. The design of the SOC AI companion was driven by researchers' participation and interactions within the SOC's daily work. SOC analysts were invited to use it during the last four months of the fieldwork. We analyzed the analysts' usage of the companion and found that in more than 90% of the cases the companion's outputs were reused by analysts in the ticket's closing report. Our results showed that when designed "in the trenches" with the intended users, a SOC AI companion can go beyond being yet another tool, but rather a system that co-evolves with its human users as it traverses through the various types of workloads. Analysts naturally started to shape the AI companion's behaviors to fit their particular needs. Our data show that the more human analysts shape the AI companion's behaviors, the more they become comfortable trusting the output from the AI system, resulting in improved productivity.