arXiv:2503.02702cs.CRcs.LG2025-03被引 12

用大模型分析日志,90%减少人工审查,提升内鬼检测效率

RedChronos: A Large Language Model-Based Log Analysis System for Insider Threat Detection in Enterprises

  • 结合大模型与智能投票、语义遗传算法,提升日志分析精度
  • 在CERT数据集上准确率、召回率均优于现有方法
  • 适合安全运营中心快速定位内部威胁,降低人力成本

内部威胁检测(IDT)旨在通过分析海量日志识别组织内部潜在或已发生的恶意行为。尽管企业有专人负责日志审查,但无法完全手动处理所有日志。针对日志数量庞大问题,本文提出基于大语言模型的RedChronos日志分析系统,创新性地引入查询感知加权投票机制和由大模型驱动变异的语义扩展遗传算法。在公开数据集CERT 4.2和5.2上,RedChronos在准确率、精确率和检测率方面优于或匹配现有方法。此外,在小红书安全运营中心实测中,系统将人工日志审查需求降低约90%。实验表明,RedChronos在内鬼检测任务中表现优异,为该领域提供了创新解决方案。未来研究可进一步优化响应速度并提升系统性能。

原文摘要 · Abstract (English)

Internal threat detection (IDT) aims to address security threats within organizations or enterprises by identifying potential or already occurring malicious threats within vast amounts of logs. Although organizations or enterprises have dedicated personnel responsible for reviewing these logs, it is impossible to manually examine all logs entirely.In response to the vast number of logs, we propose a system called RedChronos, which is a Large Language Model-Based Log Analysis System. This system incorporates innovative improvements over previous research by employing Query-Aware Weighted Voting and a Semantic Expansion-based Genetic Algorithm with LLM-driven Mutations. On the public datasets CERT 4.2 and 5.2, RedChronos outperforms or matches existing approaches in terms of accuracy, precision, and detection rate. Moreover, RedChronos reduces the need for manual intervention in security log reviews by approximately 90% in the Xiaohongshu Security Operation Center. Therefore, our RedChronos system demonstrates exceptional performance in handling IDT tasks, providing innovative solutions for these challenges. We believe that future research can continue to enhance the system's performance in IDT tasks while also reducing the response time to internal risk events.

日志分析大模型应用内鬼检测安全运维

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。