Skip to content
Preprint

BlueSTAR: Tiered Agentic Architecture for Autonomous Cyber Defense

Sep 2026 · 0 citations · 53 references
Computer Science

TL;DR

BlueSTAR is presented, a tiered agentic architecture for autonomous cyber defense in enterprise IT/OT networks that retains the fast containment of deterministic response for known threats while successfully defending against attacks requiring contextual and cross-cycle reasoning.

Abstract

Cyber attacks are increasingly automated, narrowing the time available for human analysts to detect, reason about, and respond to intrusions. Large language models (LLMs) offer a promising foundation for autonomous cyber defense because they can correlate heterogeneous evidence and reason about previously unseen threats. However, directly applying LLMs to operational security telemetry is impractical: raw logs arrive faster than current models can process them, individual events are often ambiguous, and unconstrained LLM actions can introduce significant operational risk. We present BlueSTAR, a tiered agentic architecture for autonomous cyber defense in enterprise IT/OT networks. BlueSTAR first transforms high-volume security telemetry into compact indicators of compromise. We further introduce a resilience metric that jointly captures attacker reach, impact on mission-critical assets, and disruption caused by defensive actions. We evaluate BlueSTAR on two live enterprise IT/OT cyber ranges using seven attack chains based on real-world intrusion techniques. Across attack chains, BlueSTAR retains the fast containment of deterministic response for known threats while successfully defending against attacks requiring contextual and cross-cycle reasoning, including credential theft, repeated compromise, concurrent attackers, and attacks against physical processes.

View source

Similar papers

#artificial intelligence Review Sep 2026

Trustworthy Agentic AI: A Comprehensive Cybersecurity and Systems Survey on Threat Landscapes, Defense Architectures, and Open Challenges

This survey systematically analyze threat surfaces across intra-execution loops and interaction planes, formulate a multi-layered zero-trust defense-in-depth architecture integrating Dual-LLM isolation, Capability-Based Access Control, kernel eBPF probes, and sandboxed runtimes, and map technical controls to internatio...

Seyedakbar Mostafavi · 0 citations
Sep 2026

Agentic Cybersecurity: Autonomous Threat Detection Defense Against Adversarial Metamorphic Malware Attacks

Adversarial malware evolves faster than traditional defenses can adapt. With the average breach costing $4.88 million in 2024 [1] and metamorphic malware exceeding 95% mutation rates, organizations need new approaches to detection and response. This paper presents a framework for applying agentic AI to security operati...

Víctor Manuel González-Gorrín, Josep Prieto-Blázquez · 0 citations
Preprint Aug 2026

CyberLLM: A Multi-Agent LLM Framework for Autonomous Detection and Guarded Response in Automotive Cybersecurity

CyberLLM is presented, a multi-agent, LLM-orchestrated framework that autonomously detects vulnerabilities and executes remediations under a formal, runtime safety guard, and indicates that LLM agents can perform useful autonomous cyber-defense when wrapped in a deterministic, auditable safety envelope.

Nenad Petrovic, Oussama Jeddou, Feres Ben Fraj et al. · 0 citations
Preprint Aug 2026

SysEvolve: An AI-native, safe, autonomous adversarial attack-defense co-evolutionary system

The rapid advancement of large language models (LLMs) has created a growing asymmetry in cybersecurity, where attack accelerates toward autonomous execution while defense remains predominantly human-intensive. Despite substantial prior work across cyber ranges, AI-driven attack, and AI-driven defense, this asymmetry pe...

Yuhan Meng, Shao-Fei Li, Jiong-Hao Huang et al. · 0 citations
#artificial intelligence Preprint Sep 2026

Speculative Safety Honeypot: Toward Proactive Defense Against Multi-turn Agent Attacks

As Large Language Model (LLM) agents are increasingly deployed in complex environments, multi-turn interaction attacks have become a significant security challenge. Existing detection methods typically rely on historical context. However, this retrospective logic struggles to identify deep malicious intents that are sp...

Ze-Zhong Wang, Xue-Yang Tang, Rui Lian et al. · 1 citation

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.