יום שישי, 9 באוקטובר 2026 LIVE
AI־INFO

כתבה arXiv cs.AI ·

מפלות בחקירות לאגנטים SOC יציבים: הבנת ושיפור של טרייג' תזוזות LLM

From Investigation Failures to Reliable SOC Agents: Understanding and Improving LLM-Based Alert Triage
שיפור של טרייג' תזוזות LLM במרכזי SOC עם פרקטיקה של אגנטים מרובה. המאמר עוסק בפיתוח של AIDA, פרקטיקה של אגנטים שמטרתה לשפר את טרייג' תזוזות LLM ב-SOC. AIDA מציעה פתרון לבעיית הטרייג' תזוזות LLM ב-SOC, על ידי פיתוח של פרקטיקה של אגנטים שמטרתה לשפר את טרייג' תזוזות LLM. AIDA נבנתה על ידי קבוצת מחקר של Meta AI, והיא כוללת שלושה רמזורים: AIDA-1, AIDA-2, ו-AIDA-3. AIDA-1 היא הרמזור הראשון של AIDA, והיא כוללת שלושה רמזורים: AIDA-1.1, AIDA-1.2, ו-AIDA-1.3. AIDA-2 היא הרמזור השני של AIDA, והיא כוללת שלושה רמזורים: AIDA-2.1, AIDA-2.2, ו-AIDA-2.3. AIDA-3 היא הרמזור השלישי של AIDA, והיא כוללת שלושה רמזורים: AIDA-3.1, AIDA-3.2, ו-AIDA-3.3.
תקציר מקורי באנגליתarXiv:2610.10608v1 Announce Type: cross Abstract: Security operations centers (SOCs) must triage large volumes of alerts, most of which are benign, while missed attacks can remain uninvestigated. Tool-using large language model (LLM) agents can retrieve evidence during triage, but it remains unclear how reasoning strategies determine what to gather and when an investigation is sufficient to close an alert. We study five representative approaches spanning single-pass tool use, iterative retrieval, sampled investigations, self-review, and explicit verification. To support this study, we build ALERT-BENCH, an interactive benchmark that replays enterprise telemetry through a live SIEM and requires each system to retrieve evidence. Across 1,247 alerts from a multi-stage attack scenario, every a
קרא במקור המקורי