用轻量大模型规划安全事件响应,减少错误信息并加快恢复速度。
Incident Response Planning Using a Lightweight Large Language Model with Reduced Hallucination
- 通过微调+检索+前瞻规划三步法,降低幻觉风险。
- 恢复时间比顶尖大模型快22%,且可适配多种攻击类型。
- 可在普通硬件运行,适合实战部署的中小团队使用。
及时有效的事件响应对应对日益频繁的网络攻击至关重要。然而,在复杂系统中识别正确的响应动作仍是一项重大技术挑战。利用大语言模型(LLM)中嵌入的安全知识辅助安全人员处理事件是一种有前景的方法。尽管已有研究证明其潜力,但现有方法主要依赖前沿大模型的提示工程,成本高且易产生幻觉。本文提出一种新型轻量级LLM事件响应规划方法,显著降低幻觉概率。该方法包含三个步骤:微调、信息检索与前瞻规划。理论证明,在特定假设下,幻觉概率可被控制在有限范围内,并可通过增加规划时间进一步缩小。实验基于文献中的事件日志评估,结果表明:本方法相较于前沿大模型,恢复时间最多缩短22%;且对多种事件类型和响应动作具有良好的泛化能力。整体方法轻量,可在通用硬件上运行。
原文摘要 · Abstract (English)
Timely and effective incident response is key to managing the growing frequency of cyberattacks. However, identifying the right response actions for complex systems is a major technical challenge. A promising approach to mitigate this challenge is to use the security knowledge embedded in large language models (LLMs) to assist security operators during incident handling. Recent research has demonstrated the potential of this approach, but current methods are mainly based on prompt engineering of frontier LLMs, which is costly and prone to hallucinations. We address these limitations by presenting a novel way to use an LLM for incident response planning with reduced hallucination. Our method includes three steps: fine-tuning, information retrieval, and lookahead planning. We prove that our method generates response plans with a bounded probability of hallucination and that this probability can be made arbitrarily small at the expense of increased planning time under certain assumptions. Moreover, we show that our method is lightweight and can run on commodity hardware. We evaluate our method on logs from incidents reported in the literature. The experimental results show that our method a) achieves up to 22% shorter recovery times than frontier LLMs and b) generalizes to a broad range of incident types and response actions.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。