arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.27856cs.CR

Agentic AI 网络安全框架

Agentic AI Cybersecurity Framework

  • University of Colorado Denver(科罗拉多大学丹佛分校)
  • ATLAS Institute, University of Colorado Boulder(阿特拉斯研究所,科罗拉多大学博尔德分校)

机构由 AI 辅助整理,请以论文原文为准。

Victor Kebande

AI总结:

针对传统被动网络防御的不足,提出Agentic AI网络安全框架(AACF),利用智能体实现自主、自适应防御,支持主动威胁检测与协调响应,奠定智能安全基础设施基础。

AI中文摘要:

现代网络威胁的规模、复杂性和动态性日益增加,使得传统的被动式网络安全机制已不足以应对。本文介绍了一种名为 Agentic AI 网络安全框架(AACF)的框架,旨在实现自主、目标驱动且自适应的网络防御操作。与依赖预定义规则和人工干预的传统系统不同,该框架利用智能体人工智能来感知环境状态、推理潜在威胁,并在极少监督下执行上下文感知的响应。该框架由多个关键功能层构成,包括感知、推理、决策、行动执行和反馈驱动学习,从而能够持续适应不断演变的攻击模式。通过将智能体与实时数据分析和自动化响应机制相结合,AACF 支持跨分布式环境的主动威胁检测、动态风险评估和协调缓解策略。本文提出了一个概念性架构,并展示了说明性用例,以证明其在入侵检测、事件响应和自主安全编排方面的适用性。所提出的框架为新兴的自主网络安全系统范式做出了贡献,并为开发弹性、可扩展且智能的防御基础设施奠定了基础。

英文摘要:

The increasing scale, complexity, and dynamism of modern cyber threats have rendered traditional reactive cybersecurity mechanisms insufficient. This paper introduces an Agentic AI Cybersecurity Framework (AACF) designed to enable autonomous, goal-driven, and adaptive cyber defense operations. Unlike conventional systems that rely on predefined rules and human intervention, the proposed framework leverages agentic artificial intelligence to perceive environmental states, reason about potential threats, and execute context-aware responses with minimal supervision. The framework is structured into key functional layers, including perception, reasoning, decisionmaking, action execution, and feedback-driven learning, enabling continuous adaptation to evolving attack patterns. By integrating intelligent agents with real-time data analysis and automated response mechanisms, AACF supports proactive threat detection, dynamic risk assessment, and coordinated mitigation strategies across distributed environments. A conceptual architecture is presented, along with illustrative use cases demonstrating its applicability to intrusion detection, incident response, and autonomous security orchestration. The proposed framework contributes to the emerging paradigm of self-directed cybersecurity systems and provides a foundation for developing resilient, scalable, and intelligent defense infrastructures.

↑