用大模型提升日志分析效率,减少人工错误。
LLM-based event log analysis techniques: A survey
- 利用大模型的上下文学习、微调和RAG技术自动化日志分析。
- 大模型在日志理解与分类任务中表现优于传统方法。
- 适合安全研究者和运维人员了解最新技术趋势。
事件日志分析是安全专业人员的重要任务。日志记录了计算设备上发生的活动关键信息,由于生成事件数量庞大,分析过程耗时且资源消耗高,且易出错。为应对这一挑战,研究人员开发了自动化技术以改进日志分析流程。大语言模型(LLMs)近期展现出在多种人类任务中以高水准、高速度和复杂度超越人类的能力。因此,研究者正迅速探索将LLMs应用于事件日志分析,包括微调、检索增强生成(RAG)和上下文学习等方法,这些方法显著影响性能。尽管已有良好进展,但仍需系统梳理该领域知识,识别共性与挑战,并探索未来发展方向。本文旨在综述基于大语言模型的事件日志分析技术,提供领域深度概览,指出先前研究中的空白,并展望未来可探索的方向。
原文摘要 · Abstract (English)
Event log analysis is an important task that security professionals undertake. Event logs record key information on activities that occur on computing devices, and due to the substantial number of events generated, they consume a large amount of time and resources to analyse. This demanding and repetitive task is also prone to errors. To address these concerns, researchers have developed automated techniques to improve the event log analysis process. Large Language Models (LLMs) have recently demonstrated the ability to successfully perform a wide range of tasks that individuals would usually partake in, to high standards, and at a pace and degree of complexity that outperform humans. Due to this, researchers are rapidly investigating the use of LLMs for event log analysis. This includes fine-tuning, Retrieval-Augmented Generation (RAG) and in-context learning, which affect performance. These works demonstrate good progress, yet there is a need to understand the developing body of knowledge, identify commonalities between works, and identify key challenges and potential solutions to further developments in this domain. This paper aims to survey LLM-based event log analysis techniques, providing readers with an in-depth overview of the domain, gaps identified in previous research, and concluding with potential avenues to explore in future.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。