跳到正文
arXiv:cs.CL· Georgios Koutidis, Nikolaos Kekatos, Tom Nianios, Alexios Lekidis·· 3 小时前AI 评分50

基于 NeMo-Guardrails 代理的 SIEM/XDR 受限动作 AI 修复架构

Constrained-Action AI Remediation for SIEM/XDR via a NeMo-Guardrails Proxy

AI 导读

研究团队提出一种受限动作架构,通过 SIEM/XDR 控制平面将 LLM 输出限制在封闭意图词汇表内,并用 NeMo-Guardrails 代理为 SOC 分析师 LLM 加装输入输出护栏。该代理在 SOC 专用对抗语料上将注入召回率从 25.0% 提升至 94.5%,误报率 0.1%,红队演练验证了封闭意图词汇与参数校验器可在命令跨越信任边界前拦截 LLM 失效模式。

正文

View PDF HTML (experimental)

Abstract:Security Operations Centers (SOCs) for information technology and operational technology share one incident-response problem: a flood of correlated alerts and too few analysts. Large Language Models (LLMs) are increasingly proposed as reasoning engines that triage alerts and, in autonomous deployments, issue commands that block IPs, kill processes, or quarantine files on production hosts. This coupling introduces a new risk: a single adversarial alert can become a remote code path through the LLM's reasoning, leading it to recommend an action the SOC then executes. We present a constrained-action architecture with two coordinated layers: (i) a SIEM/XDR control plane that grounds remediation in correlated host events and confines the LLM's output to a closed intent vocabulary whose templated commands are executed by thin endpoint agents, backstopped by an argument validator; and (ii) a NeMo-Guardrails proxy that wraps the SOC-analyst LLM with input- and output-rail policies, evaluated out-of-the-box against a SOC-specific adversarial corpus we release. The stock proxy lifts injection recall from 25.0% to 94.5% at a 0.1% false-positive rate, and a live red-team exercise confirms that the closed intent vocabulary and argument validator contain the observed LLM failure modes before any command crosses the trust boundary. As an architectural fit (not yet a measured operational-technology deployment), the constrained-action property suits critical-infrastructure settings where a wrong remediation has physical, not merely operational, consequences. The loop is best run human-in-the-loop or delayed: the measured rail latency keeps inline control out of scope.
Comments: 7 pages, 3 figures, 4 tables. Accepted at the 2026 IEEE International Conference on Cyber Security and Resilience (IEEE CSR 2026)
Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI); Computation and Language (cs.CL)
Cite as: arXiv:2610.09906 [cs.CR]
  (or arXiv:2610.09906v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2610.09906

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Georgios Koutidis [view email]
[v1] Wed, 7 Oct 2026 12:00:51 UTC (114 KB)

来源:arXiv:cs.CL · arxiv.org