用威胁情报提升应用安全优先级,精准识别恶意软件
TIPS: Threat Actor Informed Prioritization of Applications using SecEncoder
- 融合编码器与解码器优势,结合威胁情报分析应用
- 在真实数据集上达到0.90的F-1分数,精准识别恶意应用
- 让安全分析师调查积压减少87%,适合实战安全团队使用
本文提出TIPS:一种基于SecEncoder的专用安全语言模型,用于威胁情报驱动的应用优先级排序。TIPS结合编码器与解码器语言模型的优势,通过整合威胁行为者情报,提升检测准确性和相关性。在真实世界应用基准数据集上的大量实验表明,TIPS在识别恶意应用方面表现优异,F-1得分为0.90。此外,在实际场景中,其使安全分析师的调查积压减少了87%,显著优化了威胁响应流程并提升了整体安全态势。
原文摘要 · Abstract (English)
This paper introduces TIPS: Threat Actor Informed Prioritization using SecEncoder, a specialized language model for security. TIPS combines the strengths of both encoder and decoder language models to detect and prioritize compromised applications. By integrating threat actor intelligence, TIPS enhances the accuracy and relevance of its detections. Extensive experiments with a real-world benchmark dataset of applications demonstrate TIPS's high efficacy, achieving an F-1 score of 0.90 in identifying malicious applications. Additionally, in real-world scenarios, TIPS significantly reduces the backlog of investigations for security analysts by 87%, thereby streamlining the threat response process and improving overall security posture.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。