IRSDA: An Agent-Orchestrated Framework for Enterprise Intrusion Response
Damodar Panigrahi, Raj Patel, Shaswata Mitra, Sudip Mittal, Shahram Rahimi

TL;DR
IRSDA is an agent-based framework that autonomously detects and responds to cyber intrusions in enterprise systems by integrating AI reasoning, policy compliance, and real-time decision-making for improved security and traceability.
Contribution
The paper introduces IRSDA, a novel agent-oriented, knowledge-driven framework combining autonomic computing and AI reasoning for real-time, policy-compliant intrusion response in enterprise environments.
Findings
Demonstrated effective automation of intrusion containment.
Ensured compliance with security policies during response.
Provided traceable outputs for security analysts.
Abstract
Modern enterprise systems face escalating cyber threats that are increasingly dynamic, distributed, and multi-stage in nature. Traditional intrusion detection and response systems often rely on static rules and manual workflows, which limit their ability to respond with the speed and precision required in high-stakes environments. To address these challenges, we present the Intrusion Response System Digital Assistant (IRSDA), an agent-based framework designed to deliver autonomous and policy-compliant cyber defense. IRSDA combines Self-Adaptive Autonomic Computing Systems (SA-ACS) with the Knowledge guided Monitor, Analyze, Plan, and Execute (MAPE-K) loop to support real-time, partition-aware decision-making across enterprise infrastructure. IRSDA incorporates a knowledge-driven architecture that integrates contextual information with AI-based reasoning to support system-guided…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Software System Performance and Reliability · Information and Cyber Security
