MEGA Hub

STAIR: Effective Incident Response Using an End-to-End Agentic Planning Framework

Authors

Do you know Hanlin Jiang?You can claim authorship or link another user.Do you know Jionghao Huang?You can claim authorship or link another user.Do you know Shaofei Li?You can claim authorship or link another user.Do you know Bojia Yu?You can claim authorship or link another user.Do you know Peng Jiang?You can claim authorship or link another user.Do you know Yuxin Ren?You can claim authorship or link another user.Do you know Ning Jia?You can claim authorship or link another user.Do you know Yao Guo?You can claim authorship or link another user.Do you know Ding Li?You can claim authorship or link another user.

Abstract

Incident response planning is critical for restoring compromised software systems after cyberattacks. Common practice relies on expert-driven playbooks that encode fixed response procedures, but these static workflows struggle to adapt to evolving incident states, changing recovery objectives, and execution feedback. Recent LLM-based planners and tool-using agents improve automation, yet they remain unstable in long-horizon response because they lack a unified basis for maintaining incident state, aligning actions with the current recovery stage, and reusing historical experience. We present STAIR, an end-to-end agentic planning framework for incident response. The framework maintains the current incident as Graph-as-State, uses a Stage Router to dispatch planning to stage-specialized agents, and retrieves historical experiences to guide action selection. An Execution Harness executes actions, returns feedback to update the incident state, and validates action effects for future experience reuse. Across 100 Docker-based cyber ranges, our framework achieves a normalized defense score of 0.94 and improves over the strongest baseline by 9.5%.

Community

00

Publication notes

Author note
12 pages, 5 figures