<p>A cybersecurity framework, ELISAR, has been developed to address the evolving challenges of modern cybersecurity operations, including governance, risk management, and threat mitigation. Unlike conventional AI-driven models, ELISAR is designed as a collaborative multi-agent system, in which specialized agents are deployed to operate autonomously while interacting within a modular and scalable architecture. Multiple domain-specific agents are orchestrated by the ELISAR Engine, with each agent being optimized for distinct cybersecurity tasks. For instance, ELISAR for GRC (Governance, Risk, and Compliance) is supported by a vector-based knowledge retrieval mechanism trained on regulatory standards such as NIS2, ISO 27001, and ISO 42001, enabling compliance-driven decision-making. For penetration testing, a RAG enhanced knowledge base is utilized, curated from security assessment datasets to support proactive vulnerability exploration. The defensive suite, Blue ELISAR, is composed of intelligent sub-agents, including ELISAR Honeypots for deception, ELISAR Next-Gen Firewall for real-time detection, and ELISAR Smart DLP for adaptive data protection. Through the integration of autonomous reasoning, contextual knowledge retrieval, and real-time adaptability, ELISAR is presented as an interpretable and domain-specialized cybersecurity assistant, in contrast to monolithic LLM-based solutions. This extended version of the manuscript includes additional system design details, formal modeling, and an expanded experimental evaluation across defensive, offensive, and compliance cybersecurity domains. Improvements in accuracy, context relevance, and result stability are observed when agentic AI is combined with retrieval-based methods, while latency remains comparable across tasks.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

ELISAR: A Multi-Agent cybersecurity framework integrating retrieval-augmented generation for Blue, Red, and GRC operations

  • Sabri Allani,
  • Karam Bou-Chaaya,
  • Helmi Rais

摘要

A cybersecurity framework, ELISAR, has been developed to address the evolving challenges of modern cybersecurity operations, including governance, risk management, and threat mitigation. Unlike conventional AI-driven models, ELISAR is designed as a collaborative multi-agent system, in which specialized agents are deployed to operate autonomously while interacting within a modular and scalable architecture. Multiple domain-specific agents are orchestrated by the ELISAR Engine, with each agent being optimized for distinct cybersecurity tasks. For instance, ELISAR for GRC (Governance, Risk, and Compliance) is supported by a vector-based knowledge retrieval mechanism trained on regulatory standards such as NIS2, ISO 27001, and ISO 42001, enabling compliance-driven decision-making. For penetration testing, a RAG enhanced knowledge base is utilized, curated from security assessment datasets to support proactive vulnerability exploration. The defensive suite, Blue ELISAR, is composed of intelligent sub-agents, including ELISAR Honeypots for deception, ELISAR Next-Gen Firewall for real-time detection, and ELISAR Smart DLP for adaptive data protection. Through the integration of autonomous reasoning, contextual knowledge retrieval, and real-time adaptability, ELISAR is presented as an interpretable and domain-specialized cybersecurity assistant, in contrast to monolithic LLM-based solutions. This extended version of the manuscript includes additional system design details, formal modeling, and an expanded experimental evaluation across defensive, offensive, and compliance cybersecurity domains. Improvements in accuracy, context relevance, and result stability are observed when agentic AI is combined with retrieval-based methods, while latency remains comparable across tasks.