为高风险安全运营中的AI决策提供可管控的工程化框架
Governing AI-Assisted Security Operations: A Design Science Framework for Operational Decision Support
- 用受控查询代理分离AI规划与执行,确保操作安全
- 通过审批模板和审计追踪降低隐私、成本与决策风险
- 适合安全运维团队、技术管理者及合规负责人参考
工程管理者需在不削弱问责、隐私、成本控制和可审计性的前提下,将生成式AI、检索增强生成和编程代理引入高风险运营职能。本研究以安全运营中心(SOC)为场景,利用Kusto查询语言(KQL)和Azure安全能力构建技术实例。尽管KQL默认为只读,但AI辅助查询仍可能引发隐私泄露、成本飙升、性能下降、数据模式错误和决策偏差等风险。基于设计科学方法,提出一个受控AI查询中介系统,通过基于模式的检索、已批准模板、策略验证、只读适配器、输出标准化、可审计的代理追踪和工程评审委员会关卡,实现AI规划与实际执行的分离。贡献不在于新算法或工具,而是一套管理框架,明确设计命题、角色责任、成熟度阶段、质量关卡、评估标准和证据边界,用于治理高风险数字基础设施中的AI辅助决策。
原文摘要 · Abstract (English)
Engineering managers increasingly must decide how to introduce generative artificial intelligence (AI), retrieval-augmented generation, and coding agents into high-risk operational functions without weakening accountability, privacy, cost discipline, or auditability. The central message of this study is that AI-assisted operational decision support should be managed as a governed engineering capability before it is scaled as automation. Security operations centers (SOCs) provide a suitable setting because they combine privileged telemetry, specialist expertise, software repositories, cloud services, and evidence-sensitive decisions. This study uses Kusto Query Language (KQL) and Microsoft Azure security capabilities as a bounded technical instantiation of that broader engineering management problem. KQL is read-only in ordinary query use, but read-only does not mean risk-free: AI-assisted queries can still create privacy, cost, performance, schema-validity, and decision-quality risks through broad scans, sensitive-field exposure, stale intelligence, and misleading interpretations. Using design science research, the study develops a governed AI query-broker artifact that separates AI planning from operational execution through schema-grounded retrieval, approved templates, policy validation, read-only adapters, normalized outputs, auditable agent traces, and engineering review board gates. The contribution is not a new KQL technique, security product, or detection algorithm. Rather, the study contributes a management framework for governing AI-assisted operational decision support in high-risk digital infrastructure by specifying design propositions, role accountability, maturity stages, quality gates, evaluation criteria, and evidence boundaries.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。