用语义关系自动把威胁情报转成防火墙规则,提升安全响应速度。
From Threat Intelligence to Firewall Rules: Semantic Relations in Hybrid AI Agent and Expert System Architectures
- 利用上下位词关系从威胁报告中提取关键信息
- 生成的防火墙规则能有效阻止恶意流量,效果优于基线方法
- 适合安全自动化与智能防御系统研究者参考
网络安保需要快速应对不断演变的网络威胁。代理型人工智能(AI)虽能实现自动化,但确保安全响应的可信性至关重要。本文研究语义关系在提取敏感操作任务信息中的作用,如配置安全控制以缓解威胁。提出利用上下位词(hypernym-hyponym)文本关系,从网络安全威胁情报(CTI)报告中提取相关信息。通过神经符号方法,多智能体系统自动生成CLIPS代码,驱动专家系统生成防火墙规则以阻断恶意网络流量。实验表明,上下位词检索策略优于多种基线方法,且代理型方法在威胁缓解方面更具有效性。
原文摘要 · Abstract (English)
Web security demands rapid response capabilities to evolving cyber threats. Agentic Artificial Intelligence (AI) promises automation, but the need for trustworthy security responses is of the utmost importance. This work investigates the role of semantic relations in extracting information for sensitive operational tasks, such as configuring security controls for mitigating threats. To this end, it proposes to leverage hypernym-hyponym textual relations to extract relevant information from Cyber Threat Intelligence (CTI) reports. By leveraging a neuro-symbolic approach, the multi-agent system automatically generates CLIPS code for an expert system creating firewall rules to block malicious network traffic. Experimental results show the superior performance of the hypernym-hyponym retrieval strategy compared to various baselines and the higher effectiveness of the agentic approach in mitigating threats.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。