arXiv:2604.05440cs.CRcs.AI2026-04

LanG用AI统一安全运营,解决告警疲劳与工具碎片化问题。

LanG -- A Governance-Aware Agentic AI Platform for Unified Security Operations

  • 基于大模型的智能编排系统,支持人机协同决策
  • 规则生成器平均采纳率达96.2%,攻击链重建准确率87.5%
  • 开源可本地部署,适配多租户安全服务场景

现代安全运营中心面临告警疲劳、工具分散和跨源事件关联不足等问题,现有SIEM与XDR系统仅部分解决。本文提出开放源代码的治理感知智能体平台LanG,具备:(i) 统一事件上下文记录与相关引擎(F1=87%),(ii) 基于LangGraph的人机协同智能体编排器,(iii) 在四个基础模型上微调的LLM规则生成器,可生成可部署的Snort 2/3、Suricata和YARA规则,平均采纳率96.2%,(iv) 三阶段攻击重构器,结合Louvain社区检测、LLM假设生成与贝叶斯评分,实现87.5%杀伤链准确率,(v) 分层治理架构,所有工具通过模型上下文协议暴露,受双层护栏管道(正则+Llama Prompt Guard 2语义分类器)保护,达到98.1% F1且零误报。平台支持多租户隔离、角色权限控制与全本地部署。微调后的异常与威胁检测器在入侵检测基准中加权F1分别为99.0%和91.0%,推理耗时约21毫秒,平均检测时间1.58秒,规则生成器在真实IDS引擎上部署率超91%。与八款SOC平台的系统对比表明,LanG是唯一在单一开源工具中满足多项工业级能力并强制执行选定AI治理策略的方案。

原文摘要 · Abstract (English)

Modern Security Operations Centers struggle with alert fatigue, fragmented tooling, and limited cross-source event correlation. Challenges that current Security Information Event Management and Extended Detection and Response systems only partially address through fragmented tools. This paper presents the LLM-assisted network Governance (LanG), an open-source, governance-aware agentic AI platform for unified security operations contributing: (i) a Unified Incident Context Record with a correlation engine (F1 = 87%), (ii) an Agentic AI Orchestrator on LangGraph with human-in-the-loop checkpoints, (iii) an LLM-based Rule Generator finetuned on four base models producing deployable Snort 2/3, Suricata, and YARA rules (average acceptance rate 96.2%), (iv) a Three-Phase Attack Reconstructor combining Louvain community detection, LLM-driven hypothesis generation, and Bayesian scoring (87.5% kill-chain accuracy), and (v) a layered Governance-MCP-Agentic AI-Security architecture where all tools are exposed via the Model Context Protocol, governed by an AI Governance Policy Engine with a two-layer guardrail pipeline (regex + Llama Prompt Guard 2 semantic classifier, achieving 98.1% F1 score with experimental zero false positives). Designed for Managed Security Service Providers, the platform supports multi-tenant isolation, role-based access, and fully local deployment. Finetuned anomaly and threat detectors achieve weighted F1 scores of 99.0% and 91.0%, respectively, in intrusion-detection benchmarks, running inferences in $\approx$21 ms with a machine-side mean time to detect of 1.58 s, and the rule generator exceeds 91% deployability on live IDS engines. A systematic comparison against eight SOC platforms confirms that LanG uniquely satisfies multiple industrial capabilities all in one open-source tool, while enforcing selected AI governance policies.

安全运维智能体系统规则生成治理框架

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。