Skip to content
InfoResearchPreprintLLM-specific

Constrained-Action AI Remediation for SIEM/XDR via a NeMo-Guardrails Proxy

Published
Record updated
View JSON

Summary

The paper proposes a constrained-action architecture for LLM-driven remediation in SIEM/XDR security operations. It pairs a control plane that limits the model to a closed intent vocabulary with a NeMo-Guardrails proxy that wraps the analyst LLM. The stock proxy raises injection recall from 25.0% to 94.5% at a 0.1% false-positive rate.

Mitigation

The source describes a constrained-action design rather than a fix for a specific flaw. It confines the LLM's output to a closed intent vocabulary of templated commands executed by thin endpoint agents, backed by an argument validator, and wraps the analyst LLM with input- and output-rail policies via a NeMo-Guardrails proxy. It also suggests running the loop human-in-the-loop or delayed, since the measured rail latency rules out inline control.