Agentra用多智能体系统自动生成符合安全标准的入侵响应计划,提升效率与安全性。
Agentra: A Supervisable Multi-Agent Framework for Enterprise Intrusion Response

- 拆分响应任务给角色专用智能体,通过验证循环确保方案合理
- 在120条事件上使误报敏感的F1从0.61提升至0.84,有害操作率归零
- 适合需要可审计、可监督的自动化响应系统的安全团队
企业入侵响应仍依赖静态剧本和人工研判,导致告警与处置之间存在延迟。我们提出Agentra,一种可监管的多智能体入侵响应系统框架,将来自IDS、EDR、XDR平台的告警转化为基于MITRE ATT&CK、MITRE D3FEND和NIST CSF 2.0的结构化响应计划。Agentra通过角色化智能体分解响应推理,经由受限的规划-验证循环校验方案,通过安全网关筛选威胁情报,借助动作目录与风险评分控制执行,决策记录于不可篡改的审计日志中。我们在包含120个事件的语料库(来自ThreatHunter-Playbook、Splunk BOTSv3和DARPA OpTC)上评估,相比静态OASIS CACAO v2.0剧本基线,最优配置使误报敏感的入侵响应系统F1从0.61提升至0.84,并在规划器引发过度反应后将有害操作率恢复至0.0%的基线水平。结果表明,多智能体响应规划可在保障分析员审批与可审计性的同时,提升基于本体的响应覆盖率。
原文摘要 · Abstract (English)
Enterprise intrusion response still depends on static playbooks and analyst-driven triage, creating delay between alert generation and containment. We present Agentra, a supervisable multi-agent Intrusion Response System (IRS) framework that converts alerts from IDS, EDR, and XDR platforms into structured incident response plans grounded in MITRE ATT&CK, MITRE D3FEND, and NIST CSF 2.0. Agentra decomposes response reasoning across role-scoped agents, validates proposed plans through a bounded Planner--Validator review loop, screens retrieved threat intelligence through a Moderator security gateway, gates actions through an Action Catalog and risk score, and records decisions in an append-only audit log. We evaluate Agentra against a static OASIS CACAO v2.0 cyber-playbook baseline on a 120-event corpus drawn from ThreatHunter-Playbook, Splunk BOTSv3, and DARPA OpTC. The strongest configuration improves FP-aware IRS F1 from 0.61 to 0.84 and restores the projected harmful-action rate to the static baseline level of 0.0% after Planner-only configurations introduce unsafe overreaction. These results indicate that multi-agent response planning can improve ontology-grounded IRS coverage while preserving analyst approval and auditability.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。