用AI自动发现隐藏攻击,提升企业安全防护效率。
GenAI-Driven Threat Detection with Microsoft Security Copilot

- 构建持续运行的智能检测代理,自动分析安全事件并生成可解释告警。
- 在线评估中精准识别80.1%的新威胁,15%的案件发现此前遗漏攻击。
- 适合安全团队、运维人员使用,尤其适用于大规模企业防御场景。
应对日益复杂的网络攻击,需安全分析师不断将攻击手法转化为检测逻辑,导致防御处于被动状态。本文提出动态威胁检测代理(DTDA),一种持续运行的自适应代理,能跨Microsoft Defender系统持续调查安全事件,发现隐藏威胁并生成可解释的检测告警。DTDA融合统一活动时间线、带验证机制的LLM提示契约、规划-执行调查循环及上下文相关告警生成。集成于Microsoft Security Copilot,在数万客户中部署。120天在线评估显示,客户反馈精度达80.1%,约15%的调查案件产生新告警。离线评估中,使用GPT-5.4实现0.78 F1,较GPT-4.1提升0.12,优于基线0.26。单次事件调查平均耗时28分钟,令牌成本2.04美元,任务失败率0.38%。结果表明,自主代理可在生产规模上发现被遗漏的恶意行为。
原文摘要 · Abstract (English)
Defending against today's increasingly sophisticated cyberattacks requires security analysts to continuously translate evolving attacker tradecraft into detection logic. This places defenders in a reactive posture, requiring constantly updated expertise across an increasingly fragmented security landscape. We introduce the Dynamic Threat Detection Agent (DTDA), an always-on adaptive agent that continuously investigates security incidents across Microsoft Defender to uncover hidden threats and generate explainable detections when attack-story gaps are found. DTDA combines: (1) a unified activity timeline spanning alerts, events, user and entity behavior analytics, and threat intelligence; (2) versioned LLM prompt contracts with schema validation, grounding requirements, bounded retries, and fail-closed suppression; (3) a planner-executor investigation loop that generates attack-specific hypotheses and gathers supporting and refuting evidence; and (4) dynamic alert generation with a context-relevant title, severity, MITRE mappings, remediation guidance, implicated entities, and natural-language attack description. Integrated into Microsoft Security Copilot and deployed across tens of thousands of Defender customers, DTDA operates continuously at industry scale. In a 120-day online evaluation, DTDA achieves 80.1% precision from customer feedback while generating novel alerts for approximately 15% of investigated incidents. In offline evaluation, DTDA recovers hidden malicious activity with 0.78 F1 using GPT-5.4, improving over GPT-4.1 by 0.12 F1 and outperforming the baseline by 0.26 F1 points. Operationally, DTDA processes single-incident investigations end-to-end in a median of 28 minutes at a median token cost of USD 2.04, with a 0.38% job-level failure rate. These results demonstrate that autonomous agents can identify missed malicious activity at a production scale.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。