AI驱动的自适应网络安全测评框架研究
收稿日期: 2025-10-31
网络出版日期: 2026-04-01
基金资助
2025年度广东省教育科学规划课题(高等教育专项)(2025GXJK0655)
版权
Towards an AI-driven adaptive framework for cybersecurity assessment
Received date: 2025-10-31
Online published: 2026-04-01
Copyright
面对日益复杂和动态变化的网络威胁环境,传统静态、周期性的安全测评方法已难以有效应对。提出一种AI驱动的自适应网络安全测评框架,旨在实现测评过程的智能化、自动化与持续化。该框架构建了包含数据感知、智能分析、动态决策与反馈优化4层的闭环体系。其核心创新在于深度集成人工智能技术:利用图神经网络进行异常检测与威胁狩猎,基于深度强化学习实现自动化渗透测试与攻击路径规划,并引入大语言模型自动化生成分析报告。通过仿真实验验证,所提框架相较于传统方法,在漏洞发现深度、威胁响应速度及风险评估准确性方面均表现出显著优势,有效提升了主动防御能力,为构建动态、自适应的下一代网络安全体系提供了可行的技术路径与实践参考。
吉立建 , 林伟伟 , 段超 , 何涛 , 余村 . AI驱动的自适应网络安全测评框架研究[J]. 网络空间安全科学学报, 2025 , 3(5) : 61 -72 . DOI: 10.20172/j.issn.2097-3136.250506
Against the backdrop of an increasingly complex and dynamically evolving cyber threat landscape, traditional static and periodic cybersecurity assessment methods are no longer sufficient to address emerging challenges. An AI-driven adaptive cybersecurity assessment framework is proposed to realize the intellectualization, automation and continuity of the assessment process. The framework is constructed as a closed-loop system consisting of four layers: data perception, intelligent analysis, dynamic decision-making and feedback optimization. Its core innovation resides in the in-depth integration of artificial intelligence technologies, which involves applying Graph Neural Networks (GNN) for anomaly detection and threat hunting, adopting Deep Reinforcement Learning (DRL) to enable automated penetration testing and attack path planning, and incorporating Large Language Models (LLM) to achieve automated generation of analysis reports. Simulation experiments verify that the proposed framework exhibits remarkable advantages over traditional methods in the depth of vulnerability discovery, the speed of threat response and the accuracy of risk assessment. It can effectively improve the capability of proactive defense, and thus provide a feasible technical approach and practical reference for constructing a dynamic and adaptive next-generation cybersecurity system.
表 1 漏洞与威胁发现能力对比情况(召回率)Table 1 Comparison of vulnerability and threat detection capabilities (Recall) |
| 漏洞类型 | 召回率 | |
| 方案A | 方案B | |
| SQL注入 | 100% | 100% |
| XSS | 80% | 100% |
| 不安全的直接对象引用 | 50% | 100% |
| 复杂的权限提升链 | 0% | 75% |
表 2 漏洞与威胁发现能力对比情况(平均精确率)Table 2 Comparison of vulnerability and threat detection capabilities (Average precision) |
| 方案 | 平均精确率 |
| A | 92% |
| B | 96% |
| 1 |
IBM Security. Cost of a data breach report 2023[EB/OL]. [2025-08-12]. https://www.ibm.com/reports/data-breach.
|
| 2 |
He Z, et al. A Transformer-based deep learning approach for network intrusion detection[J/OL]. Computers & Security, 2022, 121: 102839. https://doi.org/10.1016/j.cose.2022.102839.
|
| 3 |
Microsoft. CyberBattleSim[EB/OL]. [2025-08-12]. https://github.com/microsoft/CyberBattleSim.
|
| 4 |
Schneider J, et al. Multi-agent reinforcement learning for autonomous cyber operations[C]//Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM Press, 2023: 123-135.
|
| 5 |
Risch M, et al. LLM-as-a-Soc-Analyst: evaluating the utility of large language models for security operations center tasks[PP/OL]. arXiv: 2404.01245, [2025-08-12]. https://arxiv.org/abs/2404.01245.
|
| 6 |
MLCommons. Jailbreak Benchmark: measuring AI resilience to adversarial attacks [EB/OL]. [2025-08-12]. https://mlcommons.org/en/jailbreak-benchmark-2025/.
|
| 7 |
MLCommons. MLCommons unveils new jailbreak benchmark, quantifying AI's "Resilience gap" to adversarial attacks[EB/OL]. [2025-11-12]. https://mlcommons.org.
|
| 8 |
Zhang L, et al. Malware classification with graph convolutional network on system call graphs[J]. Journal of Computer Science and Technology, 2021, 36 (5): 1097- 1111.
|
| 9 |
Wang Y, et al. Autonomous penetration testing for web applications using deep reinforcement learning[J]. Computers & Security, 2023, 124, 102956.
|
| 10 |
Alenezi M, Almustafa K. A comparative evaluation of vulnerability scanners for web applications: coverage and accuracy[J]. IEEE Access, 2024, 12, 12345- 12358.
|
| 11 |
The MITRE Corporation. D3FEND: a knowledge graph of cybersecurity countermeasures[EB/OL]. [2025-08-12]. https://d3fend.mitre.org/.
|
| 12 |
Cloud Security Alliance (CSA). Continuous adaptive security: a framework for cloud-native environments[EB/OL]. [2025-08-12]. https://cloudsecurityalliance.org.
|
| 13 |
Vinayakumar R, et al. A comparative analysis of deep learning approaches for network intrusion detection[J]. Journal of Network and Computer Applications, 2021, 191, 103147.
|
| 14 |
Zhou J, et al. Heterogeneous graph neural network for cyber attack scenario reconstruction[J]. IEEE Transactions on Information Forensics and Security, 2023, 18, 2347- 2360.
|
| 15 |
Li C, et al. MAGPIE: A Benchmark for multi-agent contextual privacy evaluation[C]//Proceedings of the 2025 AAAI Conference on Artificial Intelligence. Palo Alto: AAAI Press, 2025.
|
| 16 |
Sudhakar G, Chandra S R V, Sunitha M, et al. Hybrid AI-based threat prediction and mitigation framework for securing cloud storage[J]. The European Physical Journal Plus, 2025, 140 (10): 982.
|
| 17 |
Canadian Institute for Cybersecurity. CIC-IDS2017 dataset[EB/OL]. [2025-08-12]. https://www.unb.ca/cic/datasets/ids-2017.html.
|
| 18 |
张伟, 李静. 生成式AI驱动的网络安全漏洞评估与风险管理: 系统分类与技术演进[J] 计算机研究与发展, 2005, 62(5), 1050-1065.
Zhang W, Li J. Generative AI-driven cybersecurity vulnerability assessment and risk management: system classification and technology evolution[J]. Journal of Computer Research and Development, 2025, 62(5): 1050-1065.
|
| 19 |
Sharma A, Rani S, Shabaz M. A comprehensive review of explainable AI in cybersecurity: Decoding the black box[J]. ICT Express, 2025, 11 (6): 1200- 1219.
|
| 20 |
Sokol K, Flach P. Explainability fact sheets: a framework for systematic assessment of explainable approaches[C]//Proceedings of the 2020 Conference on Fairness, Accountability, and Transparency. New York: ACM Press, 2020: 56-67.
|
/
| 〈 |
|
〉 |