Agentic AI & RAG for Cybersecurity
Customer Challenge
The Air Force required supply chain management AI automation to review processes and cybersecurity posture while preserving oversight.
Innovative Solution
Illumination Works implemented agentic AI and RAG tools to decrease technical debt and generate reports on cybersecurity posture. Built retrieval augmented generation (RAG) technology to enhance query context with the Security Technical Implementation Guide (STIG), a rules set governing cybersecurity compliance. Leveraged knowledge graph technologies and developed agentic AI workflows connected to large language models (LLM).
Benefits/Outcomes
- Used RAG techniques to retrieve context leveraging hundreds of cybersecurity compliance rules (STIG)
- Designed Neo4j codebase as a graph database to map out repository with searchable embeddings
- Built agentic AI workflows using LLMs and assigned specific agents with jobs/responsibilities
- Created documentation agent to supply documentation to code to be opened as public request for user review
- Created code summary agent for reporting and documentation and to assist in context retrieval
- Implemented STIG RAG tool to retrieve relevant rules and STIG review tool to flag code for rules violations
Business Value
- Improves STIG compliance with fast identification of rules violations
- Automated reporting and documentation satisfies authority to operate (ATO) requirements
Toolbox
- Cybersecurity
- RAG Technologies: vector database, graph database, knowledge graph, Neo4j code base
- Agentic AI Technologies: graphRAG, documentation agent, code summary agent
Domain Expertise
- Supply chain