arXiv:2601.03287cs.CRcs.AI2026-01被引 2

用大模型自动分析日志,发现安全策略漏洞并生成可追溯的修复建议。

Automated Post-Incident Policy Gap Analysis via Threat-Informed Evidence Mapping using Large Language Models

  • 构建威胁驱动的多智能体框架,整合日志分析与策略评估
  • 在模拟暴力破解攻击中识别出3类策略缺失并生成带证据链的建议
  • 适合安全运营中心、合规团队提升事后审查效率

网络安全事后的审查对识别控制失效、提升组织韧性至关重要,但目前仍高度依赖人工,耗时且易受主观判断影响。本文研究大型语言模型(LLMs)能否自主分析系统日志,识别安全策略缺口。提出一种基于威胁情报的代理式框架,接收日志数据,将观察行为映射至MITRE ATT&CK框架,并评估组织安全策略的充分性与合规性。通过针对Windows OpenSSH服务的模拟暴力破解攻击(MITRE ATT&CK T1110),系统利用GPT-4o进行推理,LangGraph实现多智能体流程编排,LlamaIndex支持可追溯的策略检索。实验表明,该基于LLM的流水线能准确解析日志证据,识别出不足或缺失的策略控制,并生成带有明确证据-策略追溯关系的可操作修复建议。相比以往将日志分析与策略验证分开处理的工作,本研究首次实现端到端的事后审查原型系统。结果表明,大模型辅助分析有望提升事后评估的效率、一致性和可审计性,同时强调高风险决策仍需人类监督。

原文摘要 · Abstract (English)

Cybersecurity post-incident reviews are essential for identifying control failures and improving organisational resilience, yet they remain labour-intensive, time-consuming, and heavily reliant on expert judgment. This paper investigates whether Large Language Models (LLMs) can augment post-incident review workflows by autonomously analysing system evidence and identifying security policy gaps. We present a threat-informed, agentic framework that ingests log data, maps observed behaviours to the MITRE ATT&CK framework, and evaluates organisational security policies for adequacy and compliance. Using a simulated brute-force attack scenario against a Windows OpenSSH service (MITRE ATT&CK T1110), the system leverages GPT-4o for reasoning, LangGraph for multi-agent workflow orchestration, and LlamaIndex for traceable policy retrieval. Experimental results indicate that the LLM-based pipeline can interpret log-derived evidence, identify insufficient or missing policy controls, and generate actionable remediation recommendations with explicit evidence-to-policy traceability. Unlike prior work that treats log analysis and policy validation as isolated tasks, this study integrates both into a unified end-to-end proof-of-concept post-incident review framework. The findings suggest that LLM-assisted analysis has the potential to improve the efficiency, consistency, and auditability of post-incident evaluations, while highlighting the continued need for human oversight in high-stakes cybersecurity decision-making.

安全分析大模型应用事件响应

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。