用AI代理自动分析蜜罐日志,识别攻击模式
Towards Log Analysis with AI Agents: Cowrie Case Study
- 设计轻量AI代理解析原始日志
- 显著减少人工分析工作量,发现攻击模式
- 适合安全研究与自动化防御场景
真实攻击数据的稀缺严重制约网络安全研究与教育进展。尽管蜜罐如Cowrie能有效收集实时威胁情报,但其生成的海量非结构化异构日志使人工分析变得不切实际。作为安全高效AI自动化项目的第一步,本研究探索使用AI代理进行日志自动化分析。提出一种轻量级、全自动的Cowrie蜜罐日志处理方法,利用AI代理智能解析、摘要和提取原始数据中的洞察,同时考虑部署此类自主系统带来的安全影响。初步结果表明,该流程在降低人工工作量、识别攻击模式方面具有有效性,为未来更高级别的自主网络安全分析奠定基础。
原文摘要 · Abstract (English)
The scarcity of real-world attack data significantly hinders progress in cybersecurity research and education. Although honeypots like Cowrie effectively collect live threat intelligence, they generate overwhelming volumes of unstructured and heterogeneous logs, rendering manual analysis impractical. As a first step in our project on secure and efficient AI automation, this study explores the use of AI agents for automated log analysis. We present a lightweight and automated approach to process Cowrie honeypot logs. Our approach leverages AI agents to intelligently parse, summarize, and extract insights from raw data, while also considering the security implications of deploying such an autonomous system. Preliminary results demonstrate the pipeline's effectiveness in reducing manual effort and identifying attack patterns, paving the way for more advanced autonomous cybersecurity analysis in future work.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。