arXiv:2510.01751cs.AI2025-10被引 3

用标准框架匹配AI安全代理,让不同智能体各尽其责。

A cybersecurity AI agent selection and decision support framework

  • 按NIST CSF 2.0拆解安全任务,对应不同智能体能力
  • 定义三级自主度,适配组织成熟度差异
  • 实现检测、响应与治理一体化,提升防御韧性

本文提出一种结构化决策支持框架,系统性地将反应式、认知式、混合式和学习型等多样化人工智能(AI)代理架构,与美国国家标准与技术研究院(NIST)网络安全框架(CSF)2.0全面对齐。通过将NIST CSF 2.0功能细分为具体任务,该研究将自主性、自适应学习和实时响应等关键AI代理属性与各子类别的安全需求精准匹配。同时,提出辅助、增强和完全自主三级自主程度,以适应不同成熟度的组织。该综合方法超越孤立的AI应用,构建统一的检测、事件响应与治理策略。概念验证表明,定制化的AI代理部署可契合实际约束与风险特征,显著提升态势感知能力、加快响应速度,并通过自适应风险管理强化长期韧性。本研究弥合了理论AI与实际安全需求之间的差距,为符合行业标准的实证驱动多智能体系统奠定基础。

原文摘要 · Abstract (English)

This paper presents a novel, structured decision support framework that systematically aligns diverse artificial intelligence (AI) agent architectures, reactive, cognitive, hybrid, and learning, with the comprehensive National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0. By integrating agent theory with industry guidelines, this framework provides a transparent and stepwise methodology for selecting and deploying AI solutions to address contemporary cyber threats. Employing a granular decomposition of NIST CSF 2.0 functions into specific tasks, the study links essential AI agent properties such as autonomy, adaptive learning, and real-time responsiveness to each subcategory's security requirements. In addition, it outlines graduated levels of autonomy (assisted, augmented, and fully autonomous) to accommodate organisations at varying stages of cybersecurity maturity. This holistic approach transcends isolated AI applications, providing a unified detection, incident response, and governance strategy. Through conceptual validation, the framework demonstrates how tailored AI agent deployments can align with real-world constraints and risk profiles, enhancing situational awareness, accelerating response times, and fortifying long-term resilience via adaptive risk management. Ultimately, this research bridges the gap between theoretical AI constructs and operational cybersecurity demands, establishing a foundation for robust, empirically validated multi-agent systems that adhere to industry standards.

AI安全智能体NIST框架决策支持

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。