LATIDIA · Ciberseguridad
Diseño y evaluación de un subsistema controlado de orquestación y respuesta a incidentes posteriores a la alerta utilizando un motor de reglas y un modelo de lenguaje grande local
arXiv:2609.26316v1 Announce Type: new Abstract: This paper presents a controlled post-alert incident orchestration and response subsystem for educational information systems. La arquitectura separa las clas deterministas
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.26316v1 Announce Type: new Abstract: This paper presents a controlled post-alert incident orchestration and response subsystem for educational information systems. The architecture separates deterministic classification, contextual analysis, human approval, and technical execution. A Rule Engine determines severity and selects the playbook, while Static RAG and a local large language model provide advisory content under Validator, Guardrail, Output Sanitizer, and Safe Fallback controls. Experiments begin after simulated alerts are stored in Elasticsearch. The Rule Engine matched the predefined routing matrix in all 30 boundary cases. The Durable Queue completed 100 events without duplicate tasks, new failed tasks, or unintended firewall rules. An eight-alert contention experiment preserved the configured limit of one