BlueSTAR: Tiered Agentic Architecture for Autonomous Cyber Defense

📅 2026-09-10
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
为解决自动化网络攻击的快速响应问题,BlueSTAR通过分层代理架构和大型语言模型处理安全遥测数据,实现对已知和未知威胁的有效防御。
📝 Abstract
Cyber attacks are increasingly automated, narrowing the time available for human analysts to detect, reason about, and respond to intrusions. Large language models (LLMs) offer a promising foundation for autonomous cyber defense because they can correlate heterogeneous evidence and reason about previously unseen threats. However, directly applying LLMs to operational security telemetry is impractical: raw logs arrive faster than current models can process them, individual events are often ambiguous, and unconstrained LLM actions can introduce significant operational risk. We present BlueSTAR, a tiered agentic architecture for autonomous cyber defense in enterprise IT/OT networks. BlueSTAR first transforms high-volume security telemetry into compact indicators of compromise. We further introduce a resilience metric that jointly captures attacker reach, impact on mission-critical assets, and disruption caused by defensive actions. We evaluate BlueSTAR on two live enterprise IT/OT cyber ranges using seven attack chains based on real-world intrusion techniques. Across attack chains, BlueSTAR retains the fast containment of deterministic response for known threats while successfully defending against attacks requiring contextual and cross-cycle reasoning, including credential theft, repeated compromise, concurrent attackers, and attacks against physical processes.
Problem

Research questions and friction points this paper is trying to address.

cyber attacks
large language models
autonomous cyber defense
security telemetry
operational risk
Innovation

Methods, ideas, or system contributions that make the work stand out.

Tiered Agentic Architecture
Autonomous Cyber Defense
Resilience Metric
Contextual and Cross-cycle Reasoning
🔎 Similar Papers
No similar papers found.