arXiv:2504.00428cs.CRcs.AI2025-04被引 14

用大模型+实时情报,自动识别最新漏洞威胁

LLM-Assisted Proactive Threat Intelligence for Automated Reasoning

  • 结合GPT-4o与RAG技术,动态接入漏洞、漏洞利用等实时数据
  • 对新披露漏洞、已知被利用漏洞的响应速度提升显著
  • 适合安全运营中心、自动化防御系统研发人员使用

应对不断演化的网络威胁需要先进而复杂的手段。本研究提出一种新方法,通过将大语言模型(LLM)与检索增强生成(RAG)系统结合持续威胁情报源,提升实时网络安全威胁检测与响应能力。利用GPT-4o及RAG技术,克服传统静态分析的局限,实现对实时数据的动态整合。采用Patrowl框架自动获取包括CVE、CWE、EPSS和KEV在内的多元威胁情报,使用all-mpnet-base-v2模型生成高维向量嵌入,并在Milvus中存储与查询。案例研究显示,该系统在处理新披露漏洞、已知被利用漏洞(KEV)及高EPSS评分的CVE方面,显著优于基线GPT-4o。本工作不仅拓展了大模型在网络安全中的应用,也为自动化智能威胁信息管理系统的构建奠定坚实基础,弥补当前实践中的关键空白。

原文摘要 · Abstract (English)

Successful defense against dynamically evolving cyber threats requires advanced and sophisticated techniques. This research presents a novel approach to enhance real-time cybersecurity threat detection and response by integrating large language models (LLMs) and Retrieval-Augmented Generation (RAG) systems with continuous threat intelligence feeds. Leveraging recent advancements in LLMs, specifically GPT-4o, and the innovative application of RAG techniques, our approach addresses the limitations of traditional static threat analysis by incorporating dynamic, real-time data sources. We leveraged RAG to get the latest information in real-time for threat intelligence, which is not possible in the existing GPT-4o model. We employ the Patrowl framework to automate the retrieval of diverse cybersecurity threat intelligence feeds, including Common Vulnerabilities and Exposures (CVE), Common Weakness Enumeration (CWE), Exploit Prediction Scoring System (EPSS), and Known Exploited Vulnerabilities (KEV) databases, and integrate these with the all-mpnet-base-v2 model for high-dimensional vector embeddings, stored and queried in Milvus. We demonstrate our system's efficacy through a series of case studies, revealing significant improvements in addressing recently disclosed vulnerabilities, KEVs, and high-EPSS-score CVEs compared to the baseline GPT-4o. This work not only advances the role of LLMs in cybersecurity but also establishes a robust foundation for the development of automated intelligent cyberthreat information management systems, addressing crucial gaps in current cybersecurity practices.

威胁情报大模型自动化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。