Autonome Cyberabwehr/Autonomous cyber defence – Methodology for risk-based autonomous cyber defence with LLM and RAG
Inhaltsverzeichnis
Bibliographische Infos

Open Access Vollzugriff
wt Werkstattstechnik online
Jahrgang 115 (2025), Heft 09
- Autor:innen:
- | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
- Verlag
- VDI fachmedien, Düsseldorf
- Copyrightjahr
- 2025
- ISSN-Online
- 1436-4980
- ISSN-Print
- 1436-4980
Kapitelinformationen
Open Access Vollzugriff
Jahrgang 115 (2025), Heft 09
Autonome Cyberabwehr/Autonomous cyber defence – Methodology for risk-based autonomous cyber defence with LLM and RAG
- Autor:innen:
- |
- ISSN-Print
- 1436-4980
- ISSN-Online
- 1436-4980
- Kapitelvorschau:
Dieser Beitrag skizziert eine Methodik für autonome Cyberabwehr in Industrie-4.0-Umgebungen, die organisatorische Risiken mit generativer KI verbindet. Durch die Kombination von LLMs, RAG und standardisierten SOPs entsteht ein strukturierter Entscheidungsprozess, der Echtzeitreaktionen und Auditierbarkeit ermöglicht. Die konzeptionellen Grundlagen, technischen Herausforderungen und Potenziale werden diskutiert. Eine prototypische Umsetzung wurde separat evaluiert.
Literaturverzeichnis
Es wurden keine Treffer gefunden. Versuchen Sie einen anderen Begriff.
- [1] Degen, F.: Lithium-ion battery cell production in Europe: Scenarios for reducing energy consumption and greenhouse gas emissions until 2030. Journal of Industrial Ecology (2023) 3, pp. 964–976 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [2] Stock, D.; Bauernhansl, T.; Weyrich, M. et al.: System Architectures for Cyber-Physical Production Systems enabling Self-X and Autonomy. IEEE International Conference on Emerging Technologies and Factory Automation (ETFA) 2020 (2020), pp. 148–155 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [3] Bitkom: Financial damage from cybercrime in Germany in 2024 (in billion euros). Internet: www.statista.com/statistics/1360289/financial-damage-cyber-crimes-germany/. Zugriff am 12.08.2025 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [4] Beerman, J.; Berent, D.; Falter, Z. et al.: A Review of Colonial Pipeline Ransomware Attack. International Symposium on Cluster, Cloud and Internet Computing Workshops (CCGridW) 2023 (2023) 23, pp. 8–15 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [5] Kushner, D.: The Real Story of Stuxnet. IEEE Spectrum (2013) 50, pp. 48–53 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [6] Adamov, A.; Carlsson, A.; Surmacz, T.: An Analysis of LockerGoga Ransomware. IEEE East-West Design & Test Symposium (EWDTS) (2019), pp. 1–5 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [7] Mekdad, Y.; Bernieri, G.; Conti, M. et al.: A threat model method for ICS malware: the TRISIS case. ACM International Conference on Computing Frontiers (2021), pp. 221–228 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [8] Scarfone, K.; Mell, P.: Guide to Intrusion Detection and Prevention Systems (IDPS). NIST Special Publication 800–94 (2007), doi.org/10.6028/NIST.SP.800–94 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [9] DIN EN ISO/IEC 27001: Informationssicherheit, Cybersicherheit und Datenschutz – Informationssicherheitsmanagementsysteme – Anforderungen (ISO/IEC 27001:2022). Deutsche Fassung EN ISO/IEC 27001:2023, Ausgabe 2024–01 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [10] Dhirani, L.; Armstrong, E.; Newe, T.: Industrial IoT, Cyber Threats, and Standards Landscape: Evaluation and Roadmap. Sensors 2021 (2021) 21, #3901 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [11] European Union Agency for Cyber-Security: ENISA Threat Landscape for Industrial Control Systems 2024. Internet: www.enisa.europa.eu/publications/enisa-threat-landscape-2024 . Zugriff am 12.08.2025 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [12] Cao, C.; Wang, F.; Lindley, L. et al.: Managing Linux servers with LLM-based AI agents: An empirical evaluation with GPT4. Machine Learning with Applications 17 (2024) #100570, doi.org/10.1016/j.mlwa.2024.100570 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [13] Xu, H.; Wang, S.; Li, N. et al.: Large Language Models for Cyber Security: A Systematic Literature Review. arXiv preprint 2405.04760, doi.org/10.48550/arXiv.2405.04760 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [14] Liu, O.; Fu, D.; Yogatama, D. et al.: DeLLMa: Decision Making Under Uncertainty with Large Language Models. arXiv preprint 2024, doi.org/10.48550/arXiv.2402.02392 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [15] Li, S.; Puig, X.; Paxton, C. et al.: Pre-Trained Language Models for Interactive Decision-Making. arXiv preprint 2022, doi.org/10.48550/arXiv.2202.01771 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [16] Gokcimen, T.; Das, B.: A novel system for strengthening security in large language models against hallucination and injection attacks with effective strategies. Alexandria Engineering Journal 123 (2025), pp. 71–90 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [17] Wang, W.; Wang, Y.; Joty, S. et al.: RAP-Gen: Retrieval-Augmented Patch Generation with CodeT5 for Automatic Program Repair. ACM Joint Meeting European Software Engineering Conference and Symposium on the Foundations of Software Engineering (2023) 31, pp. 146–158 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [18] Hou, X.; Zhao, Y.; Wang, S. et al.: Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions. arXiv preprint 2025, doi.org/10.48550/arXiv.2503.23278 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [19] Geyer, M.; Schwab, J.: Risk-Aware Autonomous Defence with Generative AI: Ethical and Accountability Challenges in Cyber-Physical Infrastructures. In: Workshop on AI in Security and Defense (AI4SD) at ECAI 2025, OpenHSU Proceedings, 2025 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [20] Geyer, M.: Autonome IT-/OT-Verteidigung in der Intralogistik. Entwicklung eines resilienten KI-basierten Sicherheitssystems für die vernetzte Batteriezellenproduktion. Masterarbeit, Universität Stuttgart, 2025 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [21] CrowdStrike: The 1/10/60 Minute Challenge: A Framework for Stopping Breaches Faster. Stand: 2025. Internet: https://www.crowdstrike.com/en-us/resources/crowdcasts/the-1–10–60-minute-challenge-a-framework-for-stopping-breaches-faster/. Zugriff am 12.08.2025 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
- [22] Fraunhofer IPA: DigiBattPro 4.0 – BMBF: Digitalisierungslösungen und Materialentwicklung für die Batterieproduktion. Stand: 2025. Internet: www.ipa.fraunhofer.de/de/referenzprojekte/DigiBattPro40-BMBF.html. Zugriff am 12.08.2025 Google Scholar öffnen DOI: 10.37544/1436-4980-2025-09-21
