用安全生成式AI框架提升云安全与取证自动化能力
Automating Cloud Security and Forensics Through a Secure-by-Design Generative AI Framework
- 构建防御提示注入的语义验证系统,保障LLM输入安全
- 在真实云日志中实现93%以上检测准确率,显著提升取证效果
- 适合云安全运维与应急响应团队快速部署使用
随着云环境日益复杂,网络安全与取证调查亟需应对新型威胁。大语言模型(LLMs)虽在日志分析与推理任务中展现潜力,但仍易受提示注入攻击且缺乏取证严谨性。为此,我们提出统一的、安全优先的生成式AI框架,集成PromptShield与云取证自动化框架(CIAF)。PromptShield通过基于本体的输入验证机制,主动抵御对抗性提示,标准化用户输入并防止操纵;CIAF则通过本体驱动的结构化推理,覆盖取证全过程六个阶段,提升分析效率。我们在AWS和Microsoft Azure的真实数据集上评估系统,结果表明:在攻击条件下,PromptShield使分类精度、召回率和F1值均超过93%;CIAF利用李克特转换后的性能特征,在云日志中显著提升了勒索软件检测准确率。该框架推动了云取证与基于LLM系统的自动化、可解释性与可信度,为多样化云基础设施提供实时AI驱动的事件响应基础。
原文摘要 · Abstract (English)
As cloud environments become increasingly complex, cybersecurity and forensic investigations must evolve to meet emerging threats. Large Language Models (LLMs) have shown promise in automating log analysis and reasoning tasks, yet they remain vulnerable to prompt injection attacks and lack forensic rigor. To address these dual challenges, we propose a unified, secure-by-design GenAI framework that integrates PromptShield and the Cloud Investigation Automation Framework (CIAF). PromptShield proactively defends LLMs against adversarial prompts using ontology-driven validation that standardizes user inputs and mitigates manipulation. CIAF streamlines cloud forensic investigations through structured, ontology-based reasoning across all six phases of the forensic process. We evaluate our system on real-world datasets from AWS and Microsoft Azure, demonstrating substantial improvements in both LLM security and forensic accuracy. Experimental results show PromptShield boosts classification performance under attack conditions, achieving precision, recall, and F1 scores above 93%, while CIAF enhances ransomware detection accuracy in cloud logs using Likert-transformed performance features. Our integrated framework advances the automation, interpretability, and trustworthiness of cloud forensics and LLM-based systems, offering a scalable foundation for real-time, AI-driven incident response across diverse cloud infrastructures.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。