Constrained-Action AI Remediation for SIEM/XDR via a NeMo-Guardrails Proxy
- Published
- Record updated
Summary
The paper proposes a constrained-action architecture for LLM-driven remediation in SIEM/XDR security operations. It pairs a control plane that limits the model to a closed intent vocabulary with a NeMo-Guardrails proxy that wraps the analyst LLM. The stock proxy raises injection recall from 25.0% to 94.5% at a 0.1% false-positive rate.
Mitigation
The source describes a constrained-action design rather than a fix for a specific flaw. It confines the LLM's output to a closed intent vocabulary of templated commands executed by thin endpoint agents, backed by an argument validator, and wraps the analyst LLM with input- and output-rail policies via a NeMo-Guardrails proxy. It also suggests running the loop human-in-the-loop or delayed, since the measured rail latency rules out inline control.
Related items
- MediumCVE-2026-108583: zotero-mcp server-side request forgery via zotero_add_by_urlSimilar attack · NVD/CVE Database
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- MediumGHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messagesSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database
- Medium'AgentCorruption' Puts AWS Environments At Risk With Single PromptSimilar attack · Dark Reading