用大模型从日志推断攻击者心理,让防御更懂对手意图。
Security Logs to ATT&CK Insights: Leveraging LLMs for High-Level Threat Understanding and Cognitive Trait Inference
- 用提示词分割日志,分阶段识别攻击行为模式。
- 准确映射网络事件到MITRE ATT&CK技术,还原攻击策略。
- 首次将认知偏差引入日志分析,适合安全研究与攻防建模者。
传统网络安全依赖高阶情报和人工解析攻击链,但实时防御需从低层系统日志(如Suricata IDS日志)中直接推断攻击者意图与认知策略。本文提出一种新框架,利用大语言模型(LLMs)分析日志,将其映射至MITRE ATT&CK技术,并基于假设:攻击行为反映损失厌恶、风险偏好等认知偏差,可通过日志序列观察提取。我们设计策略驱动的提示系统,高效分割海量网络日志为不同行为阶段,使LLM能关联每阶段的可能技术及潜在认知动机。结果表明,该方法能有效弥合数据包级日志与战略意图之间的语义鸿沟,揭示工具切换、协议转换、跳板模式等行为信号对应的心理决策点,为未来行为自适应防御与认知特征推断奠定基础。
原文摘要 · Abstract (English)
Understanding adversarial behavior in cybersecurity has traditionally relied on high-level intelligence reports and manual interpretation of attack chains. However, real-time defense requires the ability to infer attacker intent and cognitive strategy directly from low-level system telemetry such as intrusion detection system (IDS) logs. In this paper, we propose a novel framework that leverages large language models (LLMs) to analyze Suricata IDS logs and infer attacker actions in terms of MITRE ATT&CK techniques. Our approach is grounded in the hypothesis that attacker behavior reflects underlying cognitive biases such as loss aversion, risk tolerance, or goal persistence that can be extracted and modeled through careful observation of log sequences. This lays the groundwork for future work on behaviorally adaptive cyber defense and cognitive trait inference. We develop a strategy-driven prompt system to segment large amounts of network logs data into distinct behavioral phases in a highly efficient manner, enabling the LLM to associate each phase with likely techniques and underlying cognitive motives. By mapping network-layer events to high-level attacker strategies, our method reveals how behavioral signals such as tool switching, protocol transitions, or pivot patterns correspond to psychologically meaningful decision points. The results demonstrate that LLMs can bridge the semantic gap between packet-level logs and strategic intent, offering a pathway toward cognitive-adaptive cyber defense. Keywords: Cognitive Cybersecurity, Large Language Models (LLMs), Cyberpsychology, Intrusion Detection Systems (IDS), MITRE ATT&CK, Cognitive Biases
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。