用多层智能体框架提升安全中心自动化响应能力
AgentSOC: A Multi-Layer Agentic AI Framework for Security Operations Automation

- 分层智能体架构整合感知、预测与风险决策
- 提升告警关联一致性,准确预判攻击意图
- 适合大型企业安全团队用于智能响应优化
安全运营中心(SOC)面临告警异构性关联难、多阶段攻击路径解析困难及响应动作选择风险高的挑战。本文提出AgentSOC,一种多层智能体AI框架,通过整合感知、前瞻推理与基于风险的行动规划,实现安全自动化。该架构包含多个抽象层级,形成统一操作闭环,支持告警标准化、上下文增强、假设生成、可行性验证及合规响应执行。在大型企业环境中概念验证显示,AgentSOC显著提升告警处置一致性,可有效预判攻击者意图,并推荐兼具可操作性与安全-影响平衡的隔离方案。基于LANL认证数据的最小可行原型验证了架构可行性。结果表明,混合式智能体推理具备构建自适应、更安全的企业级安全自动化系统的基础潜力。
原文摘要 · Abstract (English)
Security Operations Centers (SOCs) increasingly encounter difficulties in correlating heterogeneous alerts, interpreting multi-stage attack progressions, and selecting safe and effective response actions. This study introduces AgentSOC, a multi-layered agentic AI framework that enhances SOC automation by integrating perception, anticipatory reasoning, and risk-based action planning. The proposed architecture consolidates several layers of abstraction to provide a single operational loop to support normalizing alerts, enriching context, generating hypotheses, validating structural feasibility, and executing policy-compliant responses. Conceptually evaluated within a large enterprise environment, AgentSOC improves triage consistency, anticipates attackers' intentions, and provides recommended containment options that are both operationally feasible and well-balanced between security efficacy and operational impact. The results suggest that hybrid agentic reasoning has the potential to serve as a foundation for developing adaptive, safer SOC automation in large enterprises. Additionally, a minimal Proof-Of-Concept (POC) demonstration using LANL authentication data demonstrated the feasibility of the proposed architecture.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。