用大模型分析物联网安全日志,自动识别威胁并推荐应对措施。
Evaluating Language Models For Threat Detection in IoT Security Logs
- 用微调的大模型处理物联网日志,实现异常检测与建议生成。
- 多类攻击分类效果优于传统机器学习基线模型。
- 结合MITRE CAPEC知识库,提供针对性的防御建议,适合安全运维人员使用。
日志分析是网络安全领域的重要研究方向,因其能为网络与系统威胁检测提供信息来源。本文提出一种利用微调大型语言模型(LLMs)进行异常检测及缓解建议生成的流程。以经典机器学习分类器为基准,对比三种开源大模型在二分类和多分类异常检测中的表现,采用零样本、少样本提示和基于物联网数据集的微调三种策略。结果显示,大模型在多类攻击分类任务中优于基线模型。通过将检测到的威胁映射至MITRE CAPEC框架,定义一组物联网专用缓解措施,并对模型进行微调,使其能够提供检测与建议相结合的指导,提升安全响应效率。
原文摘要 · Abstract (English)
Log analysis is a relevant research field in cybersecurity as they can provide a source of information for the detection of threats to networks and systems. This paper presents a pipeline to use fine-tuned Large Language Models (LLMs) for anomaly detection and mitigation recommendation using IoT security logs. Utilizing classical machine learning classifiers as a baseline, three open-source LLMs are compared for binary and multiclass anomaly detection, with three strategies: zero-shot, few-shot prompting and fine-tuning using an IoT dataset. LLMs give better results on multi-class attack classification than the corresponding baseline models. By mapping detected threats to MITRE CAPEC, defining a set of IoT-specific mitigation actions, and fine-tuning the models with those actions, the models are able to provide a combined detection and recommendation guidance.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。