统一生成跨平台安全查询,让分析师一键适配不同日志系统。
SynRAG: A Large Language Model Framework for Executable Query Generation in Heterogeneous SIEM System
- 用通用指令自动生成适配各SIEM的查询语句。
- 在Qradar和SecOps上显著优于GPT、Llama等主流模型。
- 适合需管理多系统安全平台的运维与分析人员。
安全信息与事件管理(SIEM)系统是大型企业监控其IT基础设施的核心工具,每日需处理数百万条日志和事件。安全运营中心(SOC)分析师需从海量数据中识别潜在威胁并采取防护措施。然而,不同SIEM平台如Palo Alto Networks Qradar、Google SecOps、Splunk、Microsoft Sentinel和Elastic Stack在属性、架构及查询语言上的差异,给分析师带来了巨大挑战。由于各系统查询语法迥异,分析师需针对每种平台单独编写查询,导致培训成本高、人力需求大。为此,本文提出SynRAG框架,可将分析师编写的平台无关规范自动转化为适配多种SIEM系统的具体查询。无需SynRAG时,分析师必须手动为每个系统分别编写查询。该框架实现了跨异构SIEM环境的无缝威胁检测与事件调查,降低了对专业训练的需求。我们在代表性的Qradar和SecOps系统上评估了SynRAG,并与GPT、Llama、DeepSeek、Gemma和Claude等先进语言模型对比,结果表明,SynRAG在跨SIEM威胁检测与事件调查任务中生成的查询质量显著优于现有基线模型。
原文摘要 · Abstract (English)
Security Information and Event Management (SIEM) systems are essential for large enterprises to monitor their IT infrastructure by ingesting and analyzing millions of logs and events daily. Security Operations Center (SOC) analysts are tasked with monitoring and analyzing this vast data to identify potential threats and take preventive actions to protect enterprise assets. However, the diversity among SIEM platforms, such as Palo Alto Networks Qradar, Google SecOps, Splunk, Microsoft Sentinel and the Elastic Stack, poses significant challenges. As these systems differ in attributes, architecture, and query languages, making it difficult for analysts to effectively monitor multiple platforms without undergoing extensive training or forcing enterprises to expand their workforce. To address this issue, we introduce SynRAG, a unified framework that automatically generates threat detection or incident investigation queries for multiple SIEM platforms from a platform-agnostic specification. SynRAG can generate platformspecific queries from a single high-level specification written by analysts. Without SynRAG, analysts would need to manually write separate queries for each SIEM platform, since query languages vary significantly across systems. This framework enables seamless threat detection and incident investigation across heterogeneous SIEM environments, reducing the need for specialized training and manual query translation. We evaluate SynRAG against state-of-the-art language models, including GPT, Llama, DeepSeek, Gemma, and Claude, using Qradar and SecOps as representative SIEM systems. Our results demonstrate that SynRAG generates significantly better queries for crossSIEM threat detection and incident investigation compared to the state-of-the-art base models.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。