COHORT: Automated LLM Network Mitigation

Arxiv pdf 2026-06-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Mitigating an observed adversary in an enterprise network typically takes weeks of expert work: an analyst derives a mitigation tailored to that adversary, validates it without breaking production, and verifes it disrupts the specifc attack. The procedure relies on expert judgment and cannot safely be exercised against the production network. COHORT is the frst end-to-end framework to automate this procedure for deployable mitigations. A role-decomposed multi-agent LLM workfow proposes candidates, implements them as real device commands, and refnes them through a critique loop, all on a high-fdelity GNS3 emulator running real vendor frmware (frewall, switch, router). Each candidate is evaluated by _ofensive replay_: re-executing the original adversary on the mitigated network for a paired comparison against the unmitigated baseline, rather than the reward-signal or expert-judgment proxies used in prior simulation, hybrid, and confguration-generation work. Two further checks complement replay: a connectivity-regression check (LAN ping and internet HTTP probe) rejects mitigations that disrupt legitimate LAN or internet connectivity, and a cumulative evaluation stacks approved mitigations onto a persistent state to surface compound efects. Across three topologies and four attack scenarios (ransomware, lateral movement, DNS exfltration, data theft), 46.7% of generated mitigations both disrupt the attack and preserve connectivity under replay, 4.4the rate of a single-<agent baseline using the same model and tool access. A demo video walking through the framework is available with our released artifacts (Appendix8.3).

Loading executive summary...

LINK COPIED TO CLIPBOARD