IRSDA: An Agent-Orchestrated Framework for Enterprise Intrusion Response

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Panigrahi, Damodar, Patel, Raj, Mitra, Shaswata, Mittal, Sudip, Rahimi, Shahram
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909922383364096
author Panigrahi, Damodar
Patel, Raj
Mitra, Shaswata
Mittal, Sudip
Rahimi, Shahram
author_facet Panigrahi, Damodar
Patel, Raj
Mitra, Shaswata
Mittal, Sudip
Rahimi, Shahram
contents Modern enterprise systems face escalating cyber threats that are increasingly dynamic, distributed, and multi-stage in nature. Traditional intrusion detection and response systems often rely on static rules and manual workflows, which limit their ability to respond with the speed and precision required in high-stakes environments. To address these challenges, we present the Intrusion Response System Digital Assistant (IRSDA), an agent-based framework designed to deliver autonomous and policy-compliant cyber defense. IRSDA combines Self-Adaptive Autonomic Computing Systems (SA-ACS) with the Knowledge guided Monitor, Analyze, Plan, and Execute (MAPE-K) loop to support real-time, partition-aware decision-making across enterprise infrastructure. IRSDA incorporates a knowledge-driven architecture that integrates contextual information with AI-based reasoning to support system-guided intrusion response. The framework leverages retrieval mechanisms and structured representations to inform decision-making while maintaining alignment with operational policies. We assess the system using a representative real-world microservices application, demonstrating its ability to automate containment, enforce compliance, and provide traceable outputs for security analyst interpretation. This work outlines a modular and agent-driven approach to cyber defense that emphasizes explainability, system-state awareness, and operational control in intrusion response.
format Preprint
id arxiv_https___arxiv_org_abs_2511_19644
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle IRSDA: An Agent-Orchestrated Framework for Enterprise Intrusion Response
Panigrahi, Damodar
Patel, Raj
Mitra, Shaswata
Mittal, Sudip
Rahimi, Shahram
Cryptography and Security
Artificial Intelligence
Modern enterprise systems face escalating cyber threats that are increasingly dynamic, distributed, and multi-stage in nature. Traditional intrusion detection and response systems often rely on static rules and manual workflows, which limit their ability to respond with the speed and precision required in high-stakes environments. To address these challenges, we present the Intrusion Response System Digital Assistant (IRSDA), an agent-based framework designed to deliver autonomous and policy-compliant cyber defense. IRSDA combines Self-Adaptive Autonomic Computing Systems (SA-ACS) with the Knowledge guided Monitor, Analyze, Plan, and Execute (MAPE-K) loop to support real-time, partition-aware decision-making across enterprise infrastructure. IRSDA incorporates a knowledge-driven architecture that integrates contextual information with AI-based reasoning to support system-guided intrusion response. The framework leverages retrieval mechanisms and structured representations to inform decision-making while maintaining alignment with operational policies. We assess the system using a representative real-world microservices application, demonstrating its ability to automate containment, enforce compliance, and provide traceable outputs for security analyst interpretation. This work outlines a modular and agent-driven approach to cyber defense that emphasizes explainability, system-state awareness, and operational control in intrusion response.
title IRSDA: An Agent-Orchestrated Framework for Enterprise Intrusion Response
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2511.19644