LATIDIA · Ciberseguridad
Remediación de IA de acción restringida para SIEM/XDR a través de un proxy NeMo-Guardrails
arXiv: 2610.09906v1Tipo de anuncio: nuevo Resumen: los centros de operaciones de seguridad (SOC) para tecnología de la información y tecnología operativa comparten un problema de respuesta a incidentes: una avalancha de alertas correlacionadas y muy pocos análisis
WhatsApp ↗Telegram ↗
La noticia
arXiv:2610.09906v1 Announce Type: new Abstract: Security Operations Centers (SOCs) for information technology and operational technology share one incident-response problem: a flood of correlated alerts and too few analysts. Large Language Models (LLMs) are increasingly proposed as reasoning engines that triage alerts and, in autonomous deployments, issue commands that block IPs, kill processes, or quarantine files on production hosts. This coupling introduces a new risk: a single adversarial alert can become a remote code path through the LLM's reasoning, leading it to recommend an action the SOC then executes. We present a constrained-action architecture with two coordinated layers: (i) a SIEM/XDR control plane that grounds remediation in correlated host events and