- 状态
- 待机
- 上次检查
- 1m ago
- 置信度
- 基线
- 事件
- 0
- 权限
- 观察
- 下次检查
- 2m
NeuralOps 安全 工程
NeuralOps Autonomous Cyber Defence 工程
AI 安全 Agents, 分离式 Defence 系统 and 人类-Controlled 响应
在 VPS、Linux 服务器、网站、API、DNS 和云环境中持续观察、检测、关联并遏制基础设施威胁。
旨在尽可能多地检测、减少、遏制和响应技术能力范围内可观察到的攻击模式。
模拟 Only No Real Attack 流量
交互式 Cyber Defence 模拟
A deterministic frontend demonstration of telemetry detection, specialised parsing, 智能路由, AI analysis, 确定性验证, policy control, approval, detached response and recovery.
高影响行动需要做出决策
无需操作 will execute without explicit approval.
AI 智能体 Council
Event 时间线
SIMULATION CLOCK- 模拟 ready
分离式系统
无需持续使用 LLM- 状态
- 待机
- 上次检查
- 2m ago
- 置信度
- 基线
- 事件
- 0
- 权限
- 推荐
- 下次检查
- 3m
- 状态
- 待机
- 上次检查
- 3m ago
- 置信度
- 基线
- 事件
- 0
- 权限
- 观察
- 下次检查
- 4m
- 状态
- 待机
- 上次检查
- 4m ago
- 置信度
- 基线
- 事件
- 0
- 权限
- 推荐
- 下次检查
- 5m
- 状态
- 待机
- 上次检查
- 5m ago
- 置信度
- 基线
- 事件
- 0
- 权限
- 观察
- 下次检查
- 6m
- 状态
- 待机
- 上次检查
- 6m ago
- 置信度
- 基线
- 事件
- 0
- 权限
- 推荐
- 下次检查
- 7m
- 状态
- 待机
- 上次检查
- 7m ago
- 置信度
- 基线
- 事件
- 0
- 权限
- 观察
- 下次检查
- 8m
- 状态
- 待机
- 上次检查
- 8m ago
- 置信度
- 基线
- 事件
- 0
- 权限
- 推荐
- 下次检查
- 9m
- 状态
- 待机
- 上次检查
- 9m ago
- 置信度
- 基线
- 事件
- 0
- 权限
- 观察
- 下次检查
- 10m
- 状态
- 待机
- 上次检查
- 10m ago
- 置信度
- 基线
- 事件
- 0
- 权限
- 推荐
- 下次检查
- 11m
This demonstration uses safe, predefined frontend events only. It does not execute attacks, perform penetration testing, connect to customer 系统 or represent 实时 customer telemetry.
The 工程 问题
Modern 基础设施 Produces More 安全 Signals Than 小 Teams Can Continuously 分析
Fragmented logs, configuration drift, DNS manipulation, traffic floods, credential attacks, exposed services, CMS risk, API 滥用 and abnormal processes frequently arrive as isolated alerts. 有限 SME teams must investigate them while keeping production available.
Seven-Layer 架构
NeuralOps Cyber Defence 架构
Signals move through independent parsers, 智能路由, controlled AI 智能体, deterministic policy and detached response 系统.
遥测 and Sensors
多个专用解析器
Each parser extracts structured security facts independently. 解析器 disagreement lowers confidence, prevents automatic response, triggers verification and escalates to a human reviewer.
Smart 安全 路由
Routes each signal to a rule, signature, 阈值, parser, anomaly detector, small model, advanced reasoning model or security engineer based on severity, confidence, asset, sensitivity, blast radius, cost, urgency and required accuracy.
AI 安全 代理 Council
No agent has unrestricted authority. Important decisions use multi-agent comparison, 确定性验证, confidence thresholds, policy validation and approval gates.
政策 and 决策 引擎
分离式 Defence 系统
独立、轻量、专用的防护程序无需持续 LLM 推理即可持续运行。
Controlled 响应
通知, create an incident, collect evidence, increase monitoring, activate rate limits, temporarily block an IP, restrict exposed services, isolate suspicious processes, quarantine files, disable compromised credentials, apply temporary firewall rules, switch traffic to a protected route, generate remediation commands, verify recovery and roll back unsafe changes. ASN blocking is available only when explicitly authorised. 高-impact action requires approval unless explicitly pre-authorised.
独立 防护 Rack
分离式 Defence 系统
Each guard maintains its own state, rules, schedule, evidence, confidence, baseline, incident 历史, response permissions and rollback information.
DNS 完整性 Guard
DNS 记录, nameservers, TTL, DNSSEC visibility, certificate alignment and registrar state.
DDoS Early-警告 Guard
请求 rate, connections, SYN behaviour, endpoint repetition, geography, ASN concentration, entropy, saturation and origin health.
SSH 与凭据防护
失败 logins, spraying, stuffing, 新 keys, unusual sudo, root attempts and authentication drift.
Web 应用防护
注入指标、目录遍历、文件包含、恶意上传、管理员异常、Webshell 与篡改指标。
API 行为 Guard
数量 anomalies, token abuse, enumeration, 失败 authorisation, scraping, replay and unexpected data volume.
工艺 and Persistence Guard
新谜题 processes, parent-child anomalies, listeners, cron, systemd persistence, privilege changes and outbound connections.
文件 完整性 Guard
受保护的配置、Web 根目录、应用代码、SSH、cron、服务与敏感环境文件。
数据 数据外泄防护
出站流量、归档创建、大文件传输、云目标、导出与敏感路径访问。
CMS 防护 Guard
WordPress、Joomla、Drupal、OpenCart、Magento 和 Laravel 的变更、管理员、备份、调试模式和定时任务。
资源耗尽防护
CPU、内存、磁盘、inode、进程数、数据库连接池、工作进程、队列和日志增长。
证书与 TLS 防护
到期, issuer changes, hostname mismatch, weak protocols, chain faults, replacements and redirects.
备份 and 恢复 完整性 Guard
完成度、时效、加密、完整性测试、恢复测试、删除和异常访问。
仅靠本地软件,DNS 控制无法阻止所有形式的投毒攻击。大规模流量型 DDoS 攻击需要 CDN、Anycast、上游过滤或专用的流量清洗服务。
可辩护范围
Attack 覆盖范围 Matrix
覆盖范围 indicates observable engineering capability, not guaranteed prevention.
| 威胁 类别 | 检测 | 分离式 Guard | Possible 响应 | 人类 审批 |
|---|---|---|---|---|
| DNS 投毒指标 | 观察 / 关联 | DNS 完整性 | 校验 independent resolvers | Yes |
| DNS 劫持 | 检测 / 升级 | DNS 完整性 | 限制变更;注册商工作流 | Yes |
| DNS 放大攻击暴露 | 检测 | DNS 完整性 | 强化解析器策略 | Yes |
| Volumetric DDoS | 观察 / 升级 | DDoS 警告 | Requires 外部 Provider | 外部 |
| 协议 DDoS | 检测 / Contain | DDoS 警告 | 连接限制;服务商升级 | 政策 |
| 应用层 DDoS | 检测 / Contain | DDoS 警告 | 限流、缓存、验证挑战 | 政策 |
| 暴力破解 | 检测 / Contain | SSH 防护 | 临时来源封锁 | 政策 |
| 撞库攻击 | 关联 / 遏制 | 身份 Guard | 限制来源和令牌 | Yes |
| 密码 spraying | 检测 / 关联 | 身份 Guard | 临时速率控制 | 政策 |
| Web 漏洞利用指标 | 检测 / 关联 | Web 应用防护 | WAF 策略与证据 | Yes |
| 恶意文件上传 | 检测 / Contain | Web 应用防护 | 隔离候选文件 | Yes |
| Webshell 行为 | 关联 / 升级 | 工艺 Guard | 隔离进程并保留证据 | Yes |
| 暴露的数据库 | 检测 | 网络 Guard | 限制暴露的服务 | Yes |
| 暴露的 Redis | 检测 | 网络 Guard | 限制暴露的服务 | Yes |
| 暴露的环境变量文件 | 检测 / Contain | 文件 Guard | 限制路径并轮换密钥 | Yes |
| 权限提升指标 | 关联 / 升级 | 工艺 Guard | 终止已批准的会话 | Yes |
| 可疑的 cron 持久化 | 检测 / Contain | 工艺 Guard | 禁用任务并支持回滚 | Yes |
| 恶意进程 | 关联 / 遏制 | 工艺 Guard | 经批准后隔离 | Yes |
| 数据 exfiltration | 关联 / 升级 | 数据外泄防护 | 限制路由并保留证据 | Yes |
| API 滥用 | 检测 / Contain | API 防护 | 限流并限制令牌 | 政策 |
| 机器人流量 | 检测 / Contain | DDoS 警告 | 挑战 or rate 限制 | 政策 |
| 网页篡改 | 检测 / 关联 | 文件 Guard | 保留、隔离、恢复已批准的状态 | Yes |
| SSL 过期 | 观察 / 检测 | TLS 防护 | Renewal workflow | 政策 |
| Configuration drift | 检测 | 文件 Guard | 生成经审核的修正 | Yes |
| 供应链文件变更 | 关联 / 升级 | 文件 Guard | 隔离并验证来源 | Yes |
| 资源耗尽 | 检测 / 关联 | 资源防护 | 分类后限制工作负载 | 政策 |
事件 运营
证据 Before 操作
示例:异常的 DNS 记录变更 + 证书不匹配 + 管理员登录异常。三个独立信号在升级之前提高置信度。
- 01信号 Detected
- 02解析 and Normalise
- 03比较 基线
- 04关联 事件
- 05Calculate 置信度
- 06Classify 严重程度
- 07Select 政策
- 08审批 闸门
- 09有限 响应
- 10校验 结果
- 11不安全则回滚
- 12Preserve 证据
- 13事件 报告
- 14更新 分离式 状态
Controlled Autonomy
Four 运行中 模式
模式 1 is the default. 运行中 mode depends on deployment configuration and owner approval.
观察
只读收集、取证和报告。不更改基础设施。默认模式。
DEFAULT推荐
生成精确的修复计划。每项操作均需负责人批准。
Guarded 响应
预先批准的低风险控制、短时阻断、增强日志和自动回滚。
托管 Autonomous Defence
政策-controlled limited scope, defined blast radius, verification, human override and emergency stop.
代理 治理
Securing the 安全 Agents
The architecture is designed so untrusted log, webpage or external text cannot directly become an executable command. 时间 deployed, agents can use least-privilege 工具, isolated execution, signed definitions, strict validation, prompt-injection filtering, memory isolation, command allowlists, simulation, short-lived credentials, vault integration, integrity-protected logs, rate limits, model fallback and an emergency kill switch.
架构原则
零信任 and 身份
零信任 is not a single product. NeuralOps applies verify-explicitly, least-privilege and continuous-evaluation principles across assets, services, machines, agents and 工具.
工程 Domains
安全 工程 模块
基础设施 Defence
- Linux 服务器 审计
- SSH 加固
- 防火墙状态
- 端口 曝光
- 工艺 完整性
- 服务 Configuration
- Privilege 审核
- Persistence 检测
网络 and DNS Defence
- DNS 完整性
- Resolver 对比
- DNSSEC Visibility
- 流量 基线
- DDoS Early 警告
- 连接异常
- Outbound 网络 监控
应用防御
- 网站 安全
- API 安全
- CMS 安全
- JavaScript 曝光
- 安全 Headers
- SSL/TLS
- 文件 完整性
- Secret 曝光 检测
身份 Defence
- 登录异常
- Credential Attack 检测
- 新谜题 用户 检测
- SSH Key 监控
- 权限提升指标
- 访问 政策 Drift
事件 运营
- 关联分析
- 严重程度 Scoring
- 证据 时间线
- 响应 Planning
- 审批 工作流
- 遏制
- 恢复 验证
- 管理层 Reporting
模拟 工程 Demonstration
安全 运营 仪表盘
仅示意界面。不显示任何客户遥测数据。
完整性 and 压力
审批 and 遏制
APR-019 临时 API 令牌限制 REVIEW
APR-020 工艺 isolation request REVIEW
ACT-031 近期限流遏制 VERIFIED
RBK-006 防火墙回滚已验证 SAFE
分离式 状态 引擎
独立有状态防御
Unchanged areas do not require full rescanning. 严重 signals trigger immediate re-evaluation. 确定性 checks remain 激活 without continuous LLM usage; AI is invoked for context, ambiguity or cross-signal reasoning. 生产 state updates should be signed or integrity-protected, with corrupted state configured to 失败 safely.
dns_integrity_statetraffic_baseline_stateddos_pressure_statessh_auth_statefirewall_policy_stateprocess_integrity_statefile_integrity_stateoutbound_connection_statecms_security_stateapi_behaviour_statecertificate_stateincident_correlation_stateresponse_approval_statecontainment_staterollback_stateevidence_timeline_state部署 Models
安全 Controls Where They Are 需要
能力 depend on available permissions, infrastructure, telemetry and network position.
Lightweight VPS 部署
本地 detached guards, read-only collectors, low-resource operation and remote reporting.
私密 服务器 部署
客户控制的基础设施、私有智能体网关、VPN 或白名单访问以及本地证据。
混合 安全 部署
本地 deterministic guards, central AI analysis, encrypted telemetry and customer-controlled approvals.
SOC 集成
SIEM forwarding, webhooks, tickets, API 集成, incident escalation and evidence export.
证据 and Reporting
事件 报告 预览
报告在保留来源、置信度、局限性和审批状态的同时,对机密进行脱敏处理。
检测到敏感值,值已脱敏。
- 时间戳
- 2026-08-02 02:18 UTC
- 受影响资产
- dns-primary · web-origin-02
- 检测 source
- DNS 解析器 · TLS 防护 · 身份解析器
- 已关联 signals
- DNS 漂移 · TLS 不匹配 · 管理员异常
- 置信度
- 0.91 · independently 已验证
- 严重程度
- 高
- 疑似类别
- 账户入侵 / DNS 变更
- MITRE ATT&CK
- 在证据支持的地方进行映射
- 证据 summary
- 三个时间对齐的信号以哈希保存
- Actions performed
- 证据 preserved; monitoring increased
- 待处理 approval
- 限制 DNS 变更;撤销会话
- 回滚
- 基线 available · not executed
- 恢复 verification
- 待处理 authorised containment
- 推荐 next steps
- 验证 registrar session and rotate credentials
- 局限性
- 注册商遥测未连接
安全 and 治理
Restricted by 设计
旨在通过受限权限、策略控制、验证和回滚来最小化运营风险。
专业 免责声明
A Complementary 网络安全 工程 Layer
NeuralOps Autonomous Cyber Defence does not guarantee prevention of every attack and does not replace certified cybersecurity professionals, penetration testing, digital forensics, incident response specialists, regulatory assessments, 企业 endpoint security, upstream protection, CDN or traffic-scrubbing services.
防护 effectiveness depends on deployment architecture, granted permissions, telemetry availability, response policy, network location, upstream provider capabilities, asset configuration and human review.
对于疑似被入侵、受监管系统、支付基础设施、个人数据平台或关键基础设施,应聘请合格的网络安全专业人员。