发表机构
Iowa State University(爱荷华州立大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对DER网络,提出基于证据的威胁推理框架CyTReX,利用结构化证据包约束LLM推理,将异常警报转化为可追溯的排序威胁假设,支持SOC分诊,提升假设特异性和分析基础性。
AI 中文摘要
分布式能源资源(DER)环境依赖网络通信协议来协调边缘资产和云系统之间的控制命令、测量数据和设备状态。边缘异常检测系统(ADS)监控这些流量,以识别与正常通信行为的偏差,并标记可疑流量以供进一步调查。当ADS标记异常网络流量时,单个攻击标签通常不足以支持运营响应:该标签报告了检测器选择的类别,但未揭示可能值得调查的替代威胁解释。本文提出了基于可解释人工智能的网络安全威胁推理(CyTReX),一种用于DER安全的基于证据的威胁推理框架,该框架将网络级异常警报转换为排序的、面向分析师的威胁假设,旨在支持安全运营中心(SOC)的分诊和调查。CyTReX通过结构化证据包约束大语言模型(LLM)推理,该证据包定义为检测输出、模型解释和网络威胁情报(CTI)上下文的整合记录。证据包整合了边缘层异常检测证据、云推理层攻击解释、Shapley加性解释(SHAP)网络特征归因、替代决策规则以及支持模型上下文协议(MCP)的CTI增强。这确保了每个排序假设和攻击树分支都可追溯到明确证据,而非自由形式的LLM推理,并且不完整或冲突的证据会被传达而非抑制。在五种配置上的评估表明,额外的推理组件提高了假设特异性、证据可追溯性和分析基础性,而完整流程提供了最丰富的基于证据的推理上下文。
英文摘要
Distributed Energy Resource (DER) environments rely on network communication protocols to coordinate control commands, measurements, and device states across edge assets and cloud systems. Edge anomaly detection systems (ADS) monitor this traffic to identify deviations from normal communication behavior, flagging suspicious flows for further investigation. When the ADS flags abnormal network traffic, a single attack label is often insufficient for operational response: the label reports the detector's selected class but does not expose alternative threat interpretations that may warrant investigation. This paper presents Cybersecurity Threat Reasoning with Explainable Artificial Intelligence (CyTReX), an evidence-grounded threat reasoning framework for DER security that transforms network-level anomaly alerts into ranked, analyst-facing threat hypotheses designed to support Security Operations Center (SOC) triage and investigation. CyTReX constrains large language model (LLM) reasoning through a structured evidence packet, defined as a consolidated record of detection outputs, model explanations, and cyber threat intelligence (CTI) context. The evidence packet integrates edge-layer anomaly detection evidence, cloud reasoning layer attack interpretation, Shapley Additive Explanations (SHAP) network-feature attributions, surrogate decision rules, and Model Context Protocol (MCP)-enabled CTI enrichment. This ensures that every ranked hypothesis and attack-tree branch is traceable to explicit evidence rather than free-form LLM inference, and that incomplete or conflicting evidence is communicated rather than suppressed. Evaluation across five configurations shows that additional reasoning components improve hypothesis specificity, evidence traceability, and analytical grounding, with the complete pipeline providing the richest evidence-grounded reasoning context.
CommentsPaper Presented at the 2026 Resilience Week, National Habor, Maryland, USA