Constrained-Action AI Remediation for SIEM/XDR via a NeMo-Guardrails Proxy

📅 2026-10-07
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the security risks of remote code execution triggered by adversarial alerts in autonomous large language model (LLM) responses within Security Operations Centers (SOCs). To mitigate this vulnerability, we propose a dual-layer collaborative defense mechanism that integrates a SIEM control plane with NeMo Guardrails agents. This architecture constrains LLM outputs to a closed intent space and enforces rigorous parameter validation, thereby achieving closed-loop security governance from inference to execution. Furthermore, we construct a specialized adversarial corpus for evaluation, demonstrating a threat injection recall rate of 94.5%. Red team exercises confirm that the proposed approach effectively suppresses LLM failure modes, establishing its suitability for deployment in critical infrastructure environments.
📝 Abstract
Security Operations Centers (SOCs) for information technology and operational technology share one incident-response problem: a flood of correlated alerts and too few analysts. Large Language Models (LLMs) are increasingly proposed as reasoning engines that triage alerts and, in autonomous deployments, issue commands that block IPs, kill processes, or quarantine files on production hosts. This coupling introduces a new risk: a single adversarial alert can become a remote code path through the LLM's reasoning, leading it to recommend an action the SOC then executes. We present a constrained-action architecture with two coordinated layers: (i) a SIEM/XDR control plane that grounds remediation in correlated host events and confines the LLM's output to a closed intent vocabulary whose templated commands are executed by thin endpoint agents, backstopped by an argument validator; and (ii) a NeMo-Guardrails proxy that wraps the SOC-analyst LLM with input- and output-rail policies, evaluated out-of-the-box against a SOC-specific adversarial corpus we release. The stock proxy lifts injection recall from 25.0% to 94.5% at a 0.1% false-positive rate, and a live red-team exercise confirms that the closed intent vocabulary and argument validator contain the observed LLM failure modes before any command crosses the trust boundary. As an architectural fit (not yet a measured operational-technology deployment), the constrained-action property suits critical-infrastructure settings where a wrong remediation has physical, not merely operational, consequences. The loop is best run human-in-the-loop or delayed: the measured rail latency keeps inline control out of scope.
Problem

Research questions and friction points this paper is trying to address.

Security Operations Center
Large Language Models
adversarial alert
prompt injection
SIEM/XDR
Innovation

Methods, ideas, or system contributions that make the work stand out.

Constrained-Action Architecture
NeMo-Guardrails Proxy
Closed Intent Vocabulary
Adversarial Prompt Injection
SIEM/XDR Remediation
🔎 Similar Papers
No similar papers found.
G
Georgios Koutidis
Clone Systems, Larnaca, Cyprus
N
Nikolaos Kekatos
Clone Systems, Larnaca, Cyprus
T
Tom Nianios
Clone Systems, Larnaca, Cyprus
Alexios Lekidis
Alexios Lekidis
University of Thessaly
Smart Energy SystemsIndustrial Internet of ThingsNetwork Security