arXiv:2412.00652cs.CLcs.CR2024-12被引 10

用大模型模拟多智能体协作,提升网络安全应急响应效率。

Multi-Agent Collaboration in Incident Response with Large Language Models

  • 构建大模型智能体,模拟集中、分散与混合团队协作
  • 实验证明多智能体能提升决策速度与应对灵活性
  • 适合安全团队训练与自动化应急系统研发者参考

网络安全应急响应(IR)需要快速决策和协同行动。本文探索基于大语言模型(LLMs)的多智能体协作在真实场景中的应用,采用「后门与入侵」(Backdoors & Breaches)桌面推演游戏框架,模拟不同团队结构下的响应动态,包括集中式、去中心化及混合模式。通过分析智能体交互与表现,揭示了多智能体协作在提升决策质量、增强适应性与优化流程方面的潜力。研究结果表明,大模型可显著改善应急响应的协调性与效率,为构建更高效、自适应的网络安全防御体系提供支持。

原文摘要 · Abstract (English)

Incident response (IR) is a critical aspect of cybersecurity, requiring rapid decision-making and coordinated efforts to address cyberattacks effectively. Leveraging large language models (LLMs) as intelligent agents offers a novel approach to enhancing collaboration and efficiency in IR scenarios. This paper explores the application of LLM-based multi-agent collaboration using the Backdoors & Breaches framework, a tabletop game designed for cybersecurity training. We simulate real-world IR dynamics through various team structures, including centralized, decentralized, and hybrid configurations. By analyzing agent interactions and performance across these setups, we provide insights into optimizing multi-agent collaboration for incident response. Our findings highlight the potential of LLMs to enhance decision-making, improve adaptability, and streamline IR processes, paving the way for more effective and coordinated responses to cyber threats.

智能体协作安全应急大模型应用

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。