arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.32516cs.CRcs.AIcs.LG

REFINE:面向安全运营中心智能企业告警分诊的弹性进化框架

REFINE: A Resilient Evolution Framework for Intelligent Enterprise Alert Triage in Security Operations Centers

  • Baidu Inc.(百度公司)
  • East China Normal University(华东师范大学)

机构由 AI 辅助整理,请以论文原文为准。

Huimin Chen, Quan Long, Yanhao Wang

AI总结:

REFINE是一个LLM智能体框架,通过结构化技能编码和分析师反馈持续进化,以硬约束召回率=1.0实现企业告警分诊,在四个工业场景中优于自我进化基线。

AI中文摘要:

安全运营中心(SOC)每天处理大量告警。告警分诊在优先处理高风险威胁的同时,减少对良性告警的人工审查。LLM智能体能够对日志和威胁情报进行推理,但难以与组织特定且快速演变的SOC运营标准保持对齐。我们提出REFINE,一个用于企业告警分诊的LLM智能体框架。REFINE将分析师专业知识编码为结构化技能,并利用分析师处置反馈进行持续适应。它在进化过程中将召回率=1.0作为硬约束,以最大化误报的自动关闭,并通过结合告警分布与模型错误边界来识别判断盲点。在跨越四个MITRE ATT&CK阶段的时间划分下,对四个真实工业SOC场景进行评估:REFINE在所有进化集上达到召回率=1.0。在未来的测试窗口上,它在三个场景中保持召回率=1.0;退化案例达到0.807的召回率,仍优于自我进化基线(0.49-0.58)。

英文摘要:

Security Operations Centers (SOCs) process large volumes of alerts daily. Alert triage prioritizes high-risk threats while reducing manual review of benign alerts. LLM agents can reason over logs and threat intelligence, but struggle to keep aligned with organization-specific, rapidly evolving SOC operational standards. We introduce REFINE, an LLM-agent framework for enterprise alert triage. REFINE encodes analyst expertise as structured skills and continuously adapts using analyst disposition feedback. It enforces recall = 1.0 as a hard constraint during evolution to maximize auto-closure of false positives, and identifies judgment blind spots by combining alert distributions with model error boundaries. Evaluated on four real industrial SOC scenarios across four MITRE ATT&CK phases with temporal split: REFINE achieves recall=1.0 on all evolution sets. On future test windows, it retains recall=1.0 in three scenarios; the degraded case reaches 0.807 recall, still outperforming self-evolution baselines (0.49-0.58).

↑