arXiv:2503.18487cs.NIcs.AI2025-03中稿 · ed被引 9

用大模型提升恶意流量检测,显著增强对分布式攻击的识别能力。

Large Language Models powered Malicious Traffic Detection: Architecture, Opportunities and Case Study

  • 将大模型作为分类器、编码器和预测器,构建全流程检测架构。
  • 在地毯式DDoS攻击检测中,性能比现有系统提升近35%。
  • 适合网络安全研究者与工业界部署人员参考应用实践。

恶意流量检测是网络安保的关键技术,用于识别异常流量并发现网络攻击。大型语言模型(LLMs)在海量文本上训练,具备出色的上下文理解与常识推理能力,为网络攻击检测开辟了新路径。尽管已有研究探讨其在特定安全任务中的应用,但针对如何利用LLMs进行流量检测的系统性分析仍显不足,机会与挑战亟待厘清。本文聚焦于释放大模型在恶意流量检测中的全部潜力,提出一个完整的架构体系,涵盖预训练、微调与检测三个阶段。特别地,通过挖掘大模型的能力,我们识别出其在流量分类中可扮演的三种角色:分类器、编码器与预测器,并分别阐述其建模范式、机遇与挑战。最后,以大模型驱动的DDoS检测为例,设计了一套框架,通过利用大模型在上下文挖掘方面的优势,实现对地毯式DDoS攻击的精准识别。评估结果显示,该方法相较现有系统提升近35%的检测效能。

原文摘要 · Abstract (English)

Malicious traffic detection is a pivotal technology for network security to identify abnormal network traffic and detect network attacks. Large Language Models (LLMs) are trained on a vast corpus of text, have amassed remarkable capabilities of context-understanding and commonsense knowledge. This has opened up a new door for network attacks detection. Researchers have already initiated discussions regarding the application of LLMs on specific cyber-security tasks. Unfortunately, there remains a lack of comprehensive analysis on harnessing LLMs for traffic detection, as well as the opportunities and challenges. In this paper, we focus on unleashing the full potential of Large Language Models (LLMs) in malicious traffic detection. We present a holistic view of the architecture of LLM-powered malicious traffic detection, including the procedures of Pre-training, Fine-tuning, and Detection. Especially, by exploring the knowledge and capabilities of LLM, we identify three distinct roles LLM can act in traffic classification: Classifier, Encoder, and Predictor. For each of them, the modeling paradigm, opportunities and challenges are elaborated. Finally, we present our design on LLM-powered DDoS detection as a case study. The proposed framework attains accurate detection on carpet bombing DDoS by exploiting LLMs' capabilities in contextual mining. The evaluation shows its efficacy, exhibiting a nearly 35% improvement compared to existing systems.

大模型流量检测网络安全DDoS

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。