Skip to content
Hot eventLive

论文提出AIDA多智能体框架改进SOC告警分诊

1 reports1 sources3 hr ago updated

Get the story

AI overview

该事件围绕一项改进 SOC 告警分诊的研究展开。论文提出 AIDA 多智能体框架,用于改进基于 LLM 的安全运营中心(SOC)告警分流。后续研究进一步从调查失败角度分析并改进这类智能体:论文构建了交互基准 ALERT-BENCH,在实时 SIEM 中回放企业遥测,要求系统检索证据并处理 1,247 条多阶段攻击告警。评测显示,五种代表性方法均漏掉至少 40.4% 的攻击相关告警;追踪分析发现存在搜索无记录、同上下文复核净纠偏为负、关闭告警的调查强度不高于升级等问题。

Generated from reports · updated 3 hr ago

Timeline

Follow the coverage from different angles.

Oct 9, 2026
  1. arXiv · Multiagent Systems
    从调查失败到可靠 SOC 智能体:理解并改进基于 LLM 的告警分流

    论文构建 ALERT-BENCH 交互基准,在实时 SIEM 中回放企业遥测,要求系统检索证据并处理 1,247 条多阶段攻击告警。五种代表性方法均漏掉至少 40.4% 的攻击相关告警,追踪分析显示搜索无记录、同上下文复核净纠偏为负、关闭告警的调查强度不高于升级。

Heat trend

Current heat 9·Comparable peak 10(Oct 9)·Comparable change over 24 hours –

02.557.510Oct9Oct9Oct9Oct9

The trend compares only the same participants observed continuously; its range may be smaller than the current heat count. Move or click on the chart to inspect hourly heat; use the left and right arrow keys to switch.