With the evolution of information technology toward more advanced intelligence and automation, Security Orchestration, Automation, and Response (SOAR) has become a critical foundation for security incident handling, owing to its intelligent orchestration capabilities. Security playbooks, as the core mechanism for automated response in SOAR, require well-designed workflows and precise action matching to ensure efficient and accurate alert handling. However, with the rising sophistication of attacks and the expanding scale of security alerts, traditional expert-driven playbook recommendation approaches often degrade in recommendation quality or completely fail when existing playbook repositories cannot adequately cover unknown or novel alert scenarios. Generative Adversarial Network (GAN) offers a promising solution by capturing feature associations from existing playbooks and autonomously generating validated new playbooks tailored to previously unseen alert characteristics. Motivated by this, we propose a logic-aware, two-stage GAN-based playbook generation method in this paper. In the first stage, alert features are projected into a modeled playbook feature space to perform preliminary similarity matching. In the second stage, a hybrid strategy combining similarity-based recommendation and GAN-driven generation is used to produce and refine playbooks while preserving logical workflow integrity. Experimental results demonstrate that the proposed approach not only delivers high-precision playbook recommendations for known alert scenarios but also efficiently generates reliable playbooks for unseen alerts, achieving an average alert handling success rate of 86.55%, and thereby fulfilling response requirements in previously uncovered scenarios.
- Article type
- Year
- Co-author
Open Access
Article
Issue
Open Access
Original Article
Issue
Research on reservoir-unit division in fault-controlled oil and gas reservoirs is essential for analyzing reservoir hydrocarbon migration and accumulation. Currently, most research on reservoir-unit division has focused solely on the identification of faults and caves, employing three-dimensional spatial visualization or other methods for a simple analysis of their links. However, these approaches often lack a reasoning process that exploits the links between faults and caves for deeper insights. For such complex oil and gas reservoirs, a systematic analysis based on the interrelations between multiple geological factors is needed. Therefore, this paper proposes a graph-based method for reservoir-unit division in fault-controlled oil and gas reservoirs, enabling the representation of links between faults and caves, and it presents further systematic analysis to derive the reservoir-unit division results. A multi-attribute graph-clustering-based fault-extraction method is utilized to achieve comprehensive fault representations as fault entities. More reliable cave-instance segmentation results are obtained through attribute fusion, representing cavity entities. A graph incorporating fault and cave entities is then created. Fault entities are classified into several levels according to their spatial scale, and directed edges are utilized to represent connectivity links between faults and caves. Moreover, a connectivity analysis centered on caves was conducted using the created graph. Based on existing reservoir-unit knowledge and the cave-connectivity analysis results, reservoir-unit division was achieved. The proposed method provided reservoir-unit division results highly consistent with the information contained in seismic data, offering a new perspective for multielement integrated analysis in geophysical exploration.
京公网安备11010802044758号