Architecting the Secure AI-SOC: A Neurosymbolic Framework for Pipeline Integrity and Threat Mitigation

📅 2026-09-09
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
论文提出了一种神经符号框架,通过定制SIEM解码器和NeMo Guardrails来解决大型语言模型在安全运营中心中的间接提示注入问题。
📝 Abstract
The integration of Large Language Models (LLMs) into Security Operations Centers (SOCs) streamlines threat intelligence but introduces critical vulnerabilities, notably indirect prompt injection via log poisoning. Adversaries exploit this vector to execute multistep ``promptware'' kill chains by embedding malicious payloads within system logs to hijack the LLM's operational logic. Securing this pipeline presents a dichotomy: deterministic defenses are computationally efficient yet semantically blind, while purely neural evaluations introduce prohibitive latency and probabilistic flaws. To address this, we propose a novel neurosymbolic defense-in-depth architecture that ensures end-to-end pipeline integrity. The primary layer employs customized SIEM decoders as a deterministic pre-filter, performing immediate structural sanitization to neutralize volumetric padding and signature-based injections at the ingestion edge. The secondary layer leverages NeMo Guardrails to enforce strict semantic boundaries through self-checking validation on the structured SIEM alerts prior to LLM processing. Furthermore, the framework integrates a closed-loop telemetry system, providing critical Human-in-the-Loop (HITL) visibility into thwarted attacks directly within the SOC dashboard. We present a comprehensive experimental evaluation mapped to the MITRE ATLAS taxonomy, assessing the framework against diverse prompt injections. Our results demonstrate that this synergistic approach effectively dismantles the promptware kill chain - bounding LLM stochasticity with verifiable constraints, and delivering a resilient, highly observable defense mechanism for next-generation AI-SOCs.
Problem

Research questions and friction points this paper is trying to address.

Large Language Models
Security Operations Centers
Prompt Injection
Log Poisoning
Pipeline Integrity
Innovation

Methods, ideas, or system contributions that make the work stand out.

neurosymbolic framework
pipeline integrity
threat mitigation
customized SIEM decoders
NeMo Guardrails
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
A
Anna Gazani
Aristotle University of Thessaloniki, Greece
S
Spyridon Kounoupidis
Aristotle University of Thessaloniki, Greece
Panagiotis Katsaros
Panagiotis Katsaros
Professor of Computer Science, Aristotle University of Thessaloniki, Greece
Software SecurityVerificationModel CheckingFormal MethodsSoftware Architecture
N
Nikolaos Kekatos
Clone Systems, Cyprus
Grigorios Tsoumakas
Grigorios Tsoumakas
Aristotle University of Thessaloniki
Machine LearningData MiningKnowledge DiscoveryNatural Language Processing
G
Georgios Koutidis
Clone Systems, Cyprus