用数字孪生验证大模型推断攻击,自动制定更可靠的网络响应策略。
Hierarchical Agentic Incident Response with Digital-Twin-Validated Attack Inference

- 分层架构:大模型推断攻击路径,数字孪生校准推断结果
- 在33组件企业网络上,恢复成功率比顶尖基线高18%至31%
- 适合安全运维人员和自动化防御系统研发者
网络事件响应仍依赖人工且效率低下,因防御者需从部分观测中推断多阶段攻击,并将恢复决策转化为可靠系统命令。决策理论规划器虽能优化但依赖抽象状态与预设动作;大语言模型(LLM)可结合操作上下文推理,却可能虚构攻击与响应。为实现响应自动化,本文提出一种分层代理响应框架,融合基于LLM的攻击推断、滚动规划与数字孪生验证。微调后的LLM从安全警报和系统测量中推断攻击进展及受影响主机。模拟的网络数字孪生重演推断出的攻击,返回预测与实际效应间的差异以校准推断。独立微调的规划代理采用滚动规划法,在战术层优先处理受影响组件。在操作层,规划代理提出高层恢复动作,执行代理将其转换为恢复与验证命令,并在数字孪生中验证。我们在包含33个组件的企业网络测试平台,针对三种多阶段攻击场景评估该框架,结果显示其恢复成功率较前沿基线提升18%至31%。
原文摘要 · Abstract (English)
Network incident response remains slow and labor-intensive as the defender must infer multi-stage attacks from partial observations and translate recovery decisions into reliable system commands. Decision-theoretic planners provide principled optimization but typically rely on abstract states and predefined actions, while large language model (LLM) agents can reason over operational context but may hallucinate attacks and responses. Toward automating response planning, we present a hierarchical agentic response framework that integrates LLM-based attack inference, rollout planning, and digital-twin validation. A fine-tuned LLM infers the attack progression and affected hosts from security alerts and system measurements. An emulated network digital twin replays the inferred attack and returns discrepancies between predicted and observed effects to calibrate the inference. A separately fine-tuned planning agent uses the rollout planning method to prioritize affected components at the tactical layer. At the operational layer, the planning agent proposes high-level recovery actions, and an execution agent translates selected actions into recovery and verification commands that are validated in the digital twin. We evaluate the framework on a 33-component enterprise-network testbed under three multi-stage attack scenarios. The results show that our framework outperforms frontier-LLM baselines in recovery success rate by 18--31%.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。