Agentic AI Framework for Autonomous Cyber Threat Detection and Mitigation
DOI:
https://doi.org/10.15680/IJCTECE.2025.0806043Keywords:
Agentic AI, Autonomous Threat Detection, Large Language Models, Reinforcement Learning, Intrusion DetectionAbstract
The rising sophistication of cyberattacks, such as advanced persistent threats (APTs), ransomware, phishing attacks, insider assaults, and zero-day vulnerabilities, has posed significant challenges for traditional cybersecurity mechanisms based on static signatures and predefined rules. Existing intrusion detection and response systems are usually sluggish in decision making, have high false alarm rates and minimal adaptivity to new attack patterns. This research addresses these issues by providing an Agentic Artificial Intelligence Framework for autonomous cyber threat detection and mitigation. The suggested architecture brings together many intelligent software agents with observation, reasoning, planning, execution, learning, and collaboration skills into a single cybersecurity environment. Large Language Models provide contextual reasoning and Reinforcement Learning gradually improves mitigation measures using feedback from the environment. Retrieval-Augmented Generation provides real-time threat intelligence retrieval from security knowledge bases like as MITRE ATT&CK and CVE repositories. The Multi-Agent Coordination Layer is responsible for specialised agents for traffic monitoring, anomaly detection, vulnerability assessment, incident management, forensics, and policy management. Explainable AI modules give interpretable security decisions to boost analyst trust and meet regulatory standards. Experimental evaluation is performed on benchmark cybersecurity datasets including CICIDS2017 and Bot-IoT. The performance is measured in terms of Accuracy, Precision, Recall, F1-score, Detection Rate, False Positive Rate, Response Latency and Mitigation Success Rate. Experimental results demonstrate that the proposed Agentic AI framework significantly improves the autonomous threat detection accuracy, reduces false alarms, minimises response latency and enhances adaptive cyber resilience as compared with existing machine learning and rule-based security systems. The technology described provides an intelligent and scalable foundation for future generation autonomous Security Operations Centres capable of proactive cyber protection.
References
[1] Miyashita, S., Lian, X., Zeng, X., Matsubara, T., & Uehara, K.. Developing game AI agent behaving like human by mixing reinforcement learning and supervised learning. In 2017 18th IEEE/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing. https://doi.org/10.1109/snpd.2017.8022767
[2] Das, A., Kol, P., Lundberg, C., Doelling, K., Sevil, H. E., & Lewis, F.. A Rapid Situational Awareness Development Framework for Heterogeneous Manned-Unmanned Teams.. https://doi.org/10.1109/naecon.2018.8556769
[3] Castro-Manzano, J. M.. The Argument from Autonomy Revisited. In 2010 Ninth Mexican International Conference on Artificial Intelligence. https://doi.org/10.1109/micai.2010.30
[4] Toniuc, D., & Groza, A.. Climebot: An argumentative agent for climate change. In 2017 13th IEEE International Conference on Intelligent Computer Communication and Processing. https://doi.org/10.1109/iccp.2017.8116984
[5] P. R. Stephenson, Cyber Risk Handbook: Creating and Measuring Effective Cybersecurity Capabilities. Boca Raton, FL, USA: CRC Press, 2018.
[6] Center for Internet Security, CIS Controls Version 7.1, East Greenbush, NY, USA, 2019.
[7] P. Mell and T. Grance, "The NIST Definition of Cloud Computing," NIST Special Publication 800-145, 2011.
[8] ENISA, "Cybersecurity Guide for SMEs," European Union Agency for Cybersecurity, Heraklion, Greece, 2016.
[9] D. G. W. Birch and R. McEvoy, "Cybersecurity awareness and organisational resilience," Information Management & Computer Security, vol. 25, no. 2, pp. 145–160, 2017.
[10] S. B. Maynard, A. Ahmad, and M. Ruighaver, "Understanding the causes of information security incidents in organisations," Information Management & Computer Security, vol. 19, no. 5, pp. 300–312, 2011.

