arXiv:2410.20287cs.CRcs.AI2024-10被引 11

用AI自动化工业网络安全威胁情报,提速降耗。

AI-Driven Cyber Threat Intelligence Automation

  • 结合GPT-4o与单次微调技术,实现威胁情报自动生成。
  • 相比人工处理,报告生成效率显著提升且保持高精度。
  • 适合安全团队快速响应复杂网络威胁场景。

本研究提出一种基于微软AI安全技术的工业环境网络安全威胁情报(CTI)自动化方法。传统CTI依赖人工从威胁情报源、安全日志和暗网论坛等渠道收集、分析和解读数据,效率低下,难以应对快速传播的威胁。本文利用GPT-4o与先进的单次微调技术,构建新型自动化架构,大幅减少人工干预,同时确保最终报告的准确性。实验表明,该方案在提升威胁情报生成速度的同时,降低了对专家资源的依赖,展现出在动态威胁环境中提升响应效率与准确性的巨大潜力。

原文摘要 · Abstract (English)

This study introduces an innovative approach to automating Cyber Threat Intelligence (CTI) processes in industrial environments by leveraging Microsoft's AI-powered security technologies. Historically, CTI has heavily relied on manual methods for collecting, analyzing, and interpreting data from various sources such as threat feeds. This study introduces an innovative approach to automating CTI processes in industrial environments by leveraging Microsoft's AI-powered security technologies. Historically, CTI has heavily relied on manual methods for collecting, analyzing, and interpreting data from various sources such as threat feeds, security logs, and dark web forums -- a process prone to inefficiencies, especially when rapid information dissemination is critical. By employing the capabilities of GPT-4o and advanced one-shot fine-tuning techniques for large language models, our research delivers a novel CTI automation solution. The outcome of the proposed architecture is a reduction in manual effort while maintaining precision in generating final CTI reports. This research highlights the transformative potential of AI-driven technologies to enhance both the speed and accuracy of CTI and reduce expert demands, offering a vital advantage in today's dynamic threat landscape.

威胁情报AI自动化工业安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。