arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.10707cs.CRcs.AI

构建安全的AI-SOC:面向管道完整性与威胁缓解的神经符号框架

Architecting the Secure AI-SOC: A Neurosymbolic Framework for Pipeline Integrity and Threat Mitigation

Anna Gazani, Spyridon Kounoupidis, Panagiotis Katsaros, Nikolaos Kekatos, Grigorios Tsoumakas, Georgios Koutidis

首次发表
浏览论文内容

中文总结 AI 辅助

针对LLM集成SOC面临的日志投毒间接提示注入威胁,提出神经符号纵深防御架构,结合确定性SIEM解码器与NeMo Guardrails语义验证,有效瓦解提示软件杀伤链,保障管道完整性。

中文摘要 AI 辅助

将大型语言模型(LLM)集成到安全运营中心(SOC)中,虽然简化了威胁情报处理,但也引入了严重的安全漏洞,尤其是通过日志投毒实现的间接提示注入。攻击者利用这一攻击向量,通过在系统日志中嵌入恶意载荷来劫持LLM的操作逻辑,从而执行多步骤的“提示软件(promptware)”杀伤链。保护这一管道面临两难困境:确定性防御虽然计算高效,但在语义上存在盲区;而纯神经评估则带来过高的延迟和概率性缺陷。为解决此问题,我们提出了一种新颖的神经符号纵深防御架构,以确保端到端的管道完整性。第一层采用定制的SIEM解码器作为确定性预过滤器,在摄取边缘执行即时结构净化,以中和体积填充和基于签名的注入。第二层利用NeMo Guardrails,在LLM处理之前,通过对结构化SIEM警报进行自检查验证来强制执行严格的语义边界。此外,该框架集成了一个闭环遥测系统,直接在SOC仪表板中为受阻攻击提供关键的人工参与(HITL)可见性。我们进行了全面的实验评估,并映射到MITRE ATLAS分类法,评估了该框架针对多种提示注入的有效性。结果表明,这种协同方法有效瓦解了提示软件杀伤链——通过可验证的约束限制LLM的随机性,并为下一代AI-SOC提供了弹性强、可观测性高的防御机制。

英文摘要

The integration of Large Language Models (LLMs) into Security Operations Centers (SOCs) streamlines threat intelligence but introduces critical vulnerabilities, notably indirect prompt injection via log poisoning. Adversaries exploit this vector to execute multistep ``promptware'' kill chains by embedding malicious payloads within system logs to hijack the LLM's operational logic. Securing this pipeline presents a dichotomy: deterministic defenses are computationally efficient yet semantically blind, while purely neural evaluations introduce prohibitive latency and probabilistic flaws. To address this, we propose a novel neurosymbolic defense-in-depth architecture that ensures end-to-end pipeline integrity. The primary layer employs customized SIEM decoders as a deterministic pre-filter, performing immediate structural sanitization to neutralize volumetric padding and signature-based injections at the ingestion edge. The secondary layer leverages NeMo Guardrails to enforce strict semantic boundaries through self-checking validation on the structured SIEM alerts prior to LLM processing. Furthermore, the framework integrates a closed-loop telemetry system, providing critical Human-in-the-Loop (HITL) visibility into thwarted attacks directly within the SOC dashboard. We present a comprehensive experimental evaluation mapped to the MITRE ATLAS taxonomy, assessing the framework against diverse prompt injections. Our results demonstrate that this synergistic approach effectively dismantles the promptware kill chain - bounding LLM stochasticity with verifiable constraints, and delivering a resilient, highly observable defense mechanism for next-generation AI-SOCs.

发表机构

  • Aristotle University of Thessaloniki(塞萨洛尼基亚里士多德大学)
  • Clone Systems(克隆系统公司)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑