arXiv:2510.00311cs.CL2025-10被引 22

用多个协作智能体提升安全告警研判准确率

CORTEX: Collaborative LLM Agents for High-Stakes Alert Triage

  • 分角色智能体协同分析日志、查证证据、综合判断
  • 相比单模型方法,误报率显著降低,调查质量更高
  • 适合需要高可靠性的企业安全团队使用

安全运营中心(SOC)每日面临数万条告警,但真正威胁占比极小。传统检测流程脆弱且缺乏上下文,现有基于大模型的方法多依赖单一模型端到端处理,难以应对噪声数据且透明度低。我们提出CORTEX,一种面向高风险告警研判的多智能体架构:行为分析智能体解析操作序列,证据采集智能体查询外部系统,推理智能体整合结果生成可审计决策。为支持训练与评估,我们发布了来自生产环境的细粒度安全调查数据集,包含分析师操作步骤与工具输出。在多种企业场景中,CORTEX显著降低误报率,并优于当前最优的单智能体大模型。

原文摘要 · Abstract (English)

Security Operations Centers (SOCs) are overwhelmed by tens of thousands of daily alerts, with only a small fraction corresponding to genuine attacks. This overload creates alert fatigue, leading to overlooked threats and analyst burnout. Classical detection pipelines are brittle and context-poor, while recent LLM-based approaches typically rely on a single model to interpret logs, retrieve context, and adjudicate alerts end-to-end -- an approach that struggles with noisy enterprise data and offers limited transparency. We propose CORTEX, a multi-agent LLM architecture for high-stakes alert triage in which specialized agents collaborate over real evidence: a behavior-analysis agent inspects activity sequences, evidence-gathering agents query external systems, and a reasoning agent synthesizes findings into an auditable decision. To support training and evaluation, we release a dataset of fine-grained SOC investigations from production environments, capturing step-by-step analyst actions and linked tool outputs. Across diverse enterprise scenarios, CORTEX substantially reduces false positives and improves investigation quality over state-of-the-art single-agent LLMs.

安全智能多智能体告警研判

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。