arXiv:2504.08805cs.CRcs.LG2025-04

实证发现生成式AI显著提升安全运营效率,降低告警与故障处理时间。

Generative AI in Live Operations: Evidence of Productivity Gains in Cybersecurity and Endpoint Management

  • 通过实际运维数据对比,分析生成式AI对安全指标的影响。
  • 告警数量、重开率、分类与解决时间均显著改善。
  • 适用于关注AI提效的网络安全与终端管理团队。

我们测量了生成式AI(GAI)工具采用与四项指标之间的关联,涵盖安全运营、信息保护和端点管理:1)每起事件的告警数量;2)安全事件重开概率;3)数据泄露防护告警分类时间;4)设备策略冲突解决时间。研究发现,GAI与四项指标的显著且具有统计学与实际意义的改进相关。尽管未观测混杂因素限制了因果推断,但这些结果是首批基于真实运营数据,探究GAI采用与安全运营、数据泄露防护及设备策略管理之间关系的研究之一。

原文摘要 · Abstract (English)

We measure the association between generative AI (GAI) tool adoption and four metrics spanning security operations, information protection, and endpoint management: 1) number of security alerts per incident, 2) probability of security incident reopenings, 3) time to classify a data loss prevention alert, and 4) time to resolve device policy conflicts. We find that GAI is associated with robust and statistically and practically significant improvements in the four metrics. Although unobserved confounders inhibit causal identification, these results are among the first to use observational data from live operations to investigate the relationship between GAI adoption and security operations, data loss prevention, and device policy management.

生成式AI安全运营效能提升

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。