arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

基于NeMo-Guardrails代理的SIEM/XDR约束动作AI修复

Constrained-Action AI Remediation for SIEM/XDR via a NeMo-Guardrails Proxy

Georgios Koutidis, Nikolaos Kekatos, Tom Nianios, Alexios Lekidis

arXiv 2610.09906首次发表:更新:

发表机构

Clone Systems; University of Thessaly(Clone Systems; 色萨利大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对SOC警报过载问题,提出一种约束动作架构,通过SIEM/XDR控制平面和NeMo-Guardrails代理限制LLM输出,将注入召回率从25%提升至94.5%,并防止错误命令执行。

AI 中文摘要

信息技术和运营技术的安全运营中心(SOC)面临一个共同的 incident-response 问题:大量关联警报和过少的分析师。大型语言模型(LLMs)越来越多地被提议作为推理引擎,用于对警报进行分类,并在自主部署中发出命令,如阻止IP、终止进程或隔离生产主机上的文件。这种耦合引入了新的风险:单个对抗性警报可能通过LLM的推理成为远程代码路径,导致其推荐SOC随后执行的操作。我们提出了一种具有两个协调层的约束动作架构:(i)SIEM/XDR控制平面,将修复基于关联的主机事件,并将LLM的输出限制在封闭意图词汇表内,其模板化命令由轻量端点代理执行,并由参数验证器提供支持;(ii)NeMo-Guardrails代理,用输入和输出轨道策略包裹SOC分析师LLM,并针对我们发布的SOC特定对抗性语料库进行开箱即用评估。该现成代理将注入召回率从25.0%提升至94.5%,误报率为0.1%,实时红队演练确认,封闭意图词汇表和参数验证器在任何命令跨越信任边界之前就遏制了观察到的LLM故障模式。作为一种架构适配(尚未是实测的运营技术部署),约束动作属性适用于关键基础设施环境,在这些环境中,错误的修复会产生物理后果,而不仅仅是运营后果。该循环最好以人在环路或延迟方式运行:实测的轨道延迟使内联控制不在范围内。

英文摘要

Security Operations Centers (SOCs) for information technology and operational technology share one incident-response problem: a flood of correlated alerts and too few analysts. Large Language Models (LLMs) are increasingly proposed as reasoning engines that triage alerts and, in autonomous deployments, issue commands that block IPs, kill processes, or quarantine files on production hosts. This coupling introduces a new risk: a single adversarial alert can become a remote code path through the LLM's reasoning, leading it to recommend an action the SOC then executes. We present a constrained-action architecture with two coordinated layers: (i) a SIEM/XDR control plane that grounds remediation in correlated host events and confines the LLM's output to a closed intent vocabulary whose templated commands are executed by thin endpoint agents, backstopped by an argument validator; and (ii) a NeMo-Guardrails proxy that wraps the SOC-analyst LLM with input- and output-rail policies, evaluated out-of-the-box against a SOC-specific adversarial corpus we release. The stock proxy lifts injection recall from 25.0% to 94.5% at a 0.1% false-positive rate, and a live red-team exercise confirms that the closed intent vocabulary and argument validator contain the observed LLM failure modes before any command crosses the trust boundary. As an architectural fit (not yet a measured operational-technology deployment), the constrained-action property suits critical-infrastructure settings where a wrong remediation has physical, not merely operational, consequences. The loop is best run human-in-the-loop or delayed: the measured rail latency keeps inline control out of scope.

Comments7 pages, 3 figures, 4 tables. Accepted at the 2026 IEEE International Conference on Cyber Security and Resilience (IEEE CSR 2026)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑