STAIR: Effective Incident Response Using an End-to-End Agentic Planning Framework

📅 2026-08-10
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the limitations of traditional expert-manual-based cybersecurity response methods, which struggle to adapt to dynamic attack scenarios and evolving recovery objectives, as well as the instability of existing large-model approaches in long-horizon tasks. The authors propose an end-to-end agent planning framework that innovatively models event states using a graph structure (Graph-as-State), incorporates a phase-aware agent routing mechanism, and establishes a verifiable experience reuse loop to guide action selection and state updates. The system integrates multi-agent large language models with experience retrieval augmentation and execution feedback verification, enabling dynamic, stable, and evolvable response planning within a Docker-based network range simulation environment. Experimental results demonstrate that the proposed method achieves a normalized defense score of 0.94 across 100 simulated scenarios, representing a 9.5% improvement over the strongest baseline.
📝 Abstract
Incident response planning is critical for restoring compromised software systems after cyberattacks. Common practice relies on expert-driven playbooks that encode fixed response procedures, but these static workflows struggle to adapt to evolving incident states, changing recovery objectives, and execution feedback. Recent LLM-based planners and tool-using agents improve automation, yet they remain unstable in long-horizon response because they lack a unified basis for maintaining incident state, aligning actions with the current recovery stage, and reusing historical experience. We present STAIR, an end-to-end agentic planning framework for incident response. The framework maintains the current incident as Graph-as-State, uses a Stage Router to dispatch planning to stage-specialized agents, and retrieves historical experiences to guide action selection. An Execution Harness executes actions, returns feedback to update the incident state, and validates action effects for future experience reuse. Across 100 Docker-based cyber ranges, our framework achieves a normalized defense score of 0.94 and improves over the strongest baseline by 9.5%.
Problem

Research questions and friction points this paper is trying to address.

incident response
agentic planning
cyberattack recovery
adaptive response
state management
Innovation

Methods, ideas, or system contributions that make the work stand out.

Agentic Planning
Graph-as-State
Stage Router
Incident Response
Experience Retrieval
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
H
Hanlin Jiang
Key Laboratory of High Confidence Software Technologies, Peking University, Ministry of Education
J
Jionghao Huang
Southeast University
Shaofei Li
Shaofei Li
Peking University
Computer Security
B
Bojia Yu
Southeast University
P
Peng Jiang
Southeast University
Y
Yuxin Ren
Huawei Technologies Co., Ltd.
Ning Jia
Ning Jia
Tianjin University
Yao Guo
Yao Guo
Beijing Institute of Technology
Nanodevices
Ding Li
Ding Li
Peking University
Software EngineeringSecurity