arXiv:2605.30604cs.CRcs.AI2026-05

为金融网络安全设计可审计的智能体运行架构,实现全组织范围管控。

An Organization-Scoped LLM Agent Runtime Architecture for Regulated Cybersecurity Operations

论文配图:An Organization-Scoped LLM Agent Runtime Architecture for Regulated Cybersecurity Operations
图 1 · 摘自论文原文
  • 构建统一安全上下文,从日志触发点开始强制约束各组件行为
  • 集成现有SIEM/XDR系统,支持事件驱动与审计追踪
  • 支持分级人工介入和不可篡改审计,适合合规性要求高的场景

受监管的网络安全流程缺乏一个能跨检索、工具调用、记忆、发现、报告和审计等环节强制执行组织级范围的运行时基础架构,同时保持对模型无关性和本地部署的支持。近期大语言模型(LLM)智能体系统在孤立安全任务上表现优异,但未定义可审计的平台架构,难以满足安全运营中心(SOC)和合规工作流的需求——单个分析师的操作可能绑定整个组织。本论文提出面向金融网络安全的组织级LLM智能体运行时架构,核心是每个入口点(包括从SIEM/XDR接收的通知)生成带类型的安全部上下文,并在各组件边界强制执行。架构包含共享运行时核心、逻辑专用子智能体、受控工具适配层(暴露统一策略下的SIEM/XDR查询、增强与响应原语)、结构化带证据引用的发现、分层人工介入(HITL)门禁及追加式审计机制。模型上下文协议(MCP)、扩展遥测、渗透测试数字孪生、图谱检索与联邦知识共享作为可选扩展路径。我们定义了可实现的验证切片作为架构可测性表面,并提出包含指标级通过标准的可证伪评估方案,涵盖架构就绪度、安全策略执行、证据可追溯性、输出质量与操作可观测性。

原文摘要 · Abstract (English)

Regulated cybersecurity workflows lack a runtime substrate that enforces organization-level scope across retrieval, tool calls, memory, findings, reports, and audit while remaining model-agnostic and locally deployable. Recent large language model (LLM) agent systems report strong results on isolated cybersecurity tasks, yet they do not by themselves define an auditable platform architecture for regulated security operations centre (SOC) and compliance workflows, where a single analyst may trigger actions that bind the organization, and where the runtime must integrate with existing SIEM/XDR stacks as a primary source of context and alert-driven triggers rather than operate as a standalone analytical layer. This paper proposes an organization-scoped LLM agent runtime architecture for financial cybersecurity. The contribution is a typed Security Context that is created at every entry point, including SIEM/XDR notifications ingested as first-class triggers, and enforced at every component boundary, combined with a shared Runtime Core, logical specialist subagents, a governed Tool Adapter Layer exposing SIEM/XDR query, enrichment, and response primitives under uniform policy and audit, structured findings with evidence references, tiered human-in-the-loop (HITL) gates, and append-only audit. Model Context Protocol (MCP), extended telemetry, digital twins for pentesting, graph retrieval, and federated knowledge sharing are treated as optional extension paths rather than mandatory runtime assumptions. We describe an implementable slice as the architecture's testability surface, and we propose a falsifiable evaluation plan with metric-level pass criteria for architecture readiness, security-policy enforcement, evidence traceability, output quality, and operational observability.

LLM智能体安全审计合规运维SIEM集成

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。