arXiv:2502.14966cs.CRcs.AI2025-02被引 8

实时检测新型AI安全威胁,集成日志分析与机器学习

CyberSentinel: An Emergent Threat Detection System for AI Security

  • 单智能体系统融合日志分析、黑名单与异常检测
  • 可实时识别SSH暴力破解、钓鱼链接及未知攻击
  • 适合需要主动防御的AI系统安全团队使用

人工智能的快速发展显著扩大了AI驱动的网络安全威胁攻击面,亟需适应性防御策略。本文提出CyberSentinel,一种统一的单智能体系统,用于实时发现并缓解新兴安全风险。该系统集成三项能力:(1) 通过分析SSH日志检测暴力破解攻击,(2) 利用域名黑名单和启发式URL评分评估钓鱼威胁,(3) 基于机器学习的异常检测实现新兴威胁识别。通过持续适应不断演变的对抗策略,CyberSentinel强化了主动式网络安全防御,有效应对AI安全中的关键漏洞。

原文摘要 · Abstract (English)

The rapid advancement of artificial intelligence (AI) has significantly expanded the attack surface for AI-driven cybersecurity threats, necessitating adaptive defense strategies. This paper introduces CyberSentinel, a unified, single-agent system for emergent threat detection, designed to identify and mitigate novel security risks in real time. CyberSentinel integrates: (1) Brute-force attack detection through SSH log analysis, (2) Phishing threat assessment using domain blacklists and heuristic URL scoring, and (3) Emergent threat detection via machine learning-based anomaly detection. By continuously adapting to evolving adversarial tactics, CyberSentinel strengthens proactive cybersecurity defense, addressing critical vulnerabilities in AI security.

AI安全威胁检测实时防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。