对比开源与商用大模型在安全事件分类中的表现
On-Premise SLMs vs. Commercial LLMs: Prompt Engineering and Incident Classification in SOCs and CSIRTs
- 用五种提示工程方法测试开源模型在真实安全事件上的分类能力
- 商用模型准确率更高,但开源模型在隐私和成本上占优
- 适合关注数据安全与自主部署的网络安全团队
本研究评估了开源模型在安全事件分类中的表现,并与专有模型进行对比。使用根据 NIST SP 800-61r3 分类标准标注的匿名真实事件数据集,采用五种提示工程方法(PHP、SHP、HTP、PRP 和 ZSL)进行处理。结果表明,尽管专有模型仍具有更高的准确性,但本地部署的开源模型在隐私保护、成本效益和数据主权方面具有显著优势。
原文摘要 · Abstract (English)
In this study, we evaluate open-source models for security incident classification, comparing them with proprietary models. We utilize a dataset of anonymized real incidents, categorized according to the NIST SP 800-61r3 taxonomy and processed using five prompt-engineering techniques (PHP, SHP, HTP, PRP, and ZSL). The results indicate that, although proprietary models still exhibit higher accuracy, locally deployed open-source models provide advantages in privacy, cost-effectiveness, and data sovereignty.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。