AI Agents 相关度: 9/10

From Threat Intelligence to Firewall Rules: Semantic Relations in Hybrid AI Agent and Expert System Architectures

Chiara Bonfanti, Davide Colaiacomo, Luca Cagliero, Cataldo Basile
arXiv: 2603.03911v1 发布: 2026-03-04 更新: 2026-03-04

AI 摘要

利用语义关系,混合AI Agent和专家系统自动生成防火墙规则,提升网络安全响应速度。

主要贡献

  • 提出基于超类-子类关系的威胁情报提取方法
  • 构建基于神经符号方法的多Agent系统
  • 自动化生成CLIPS代码配置防火墙规则

方法论

采用神经符号方法,构建多Agent系统,利用超类-子类关系从威胁情报报告中提取信息,驱动专家系统生成防火墙规则。

原文摘要

Web security demands rapid response capabilities to evolving cyber threats. Agentic Artificial Intelligence (AI) promises automation, but the need for trustworthy security responses is of the utmost importance. This work investigates the role of semantic relations in extracting information for sensitive operational tasks, such as configuring security controls for mitigating threats. To this end, it proposes to leverage hypernym-hyponym textual relations to extract relevant information from Cyber Threat Intelligence (CTI) reports. By leveraging a neuro-symbolic approach, the multi-agent system automatically generates CLIPS code for an expert system creating firewall rules to block malicious network traffic. Experimental results show the superior performance of the hypernym-hyponym retrieval strategy compared to various baselines and the higher effectiveness of the agentic approach in mitigating threats.

标签

AI Agent Cyber Threat Intelligence Firewall Rules Semantic Relations Expert System

arXiv 分类

cs.AI cs.CL cs.CR