arXiv:2603.23966cs.CRcs.AI2026-03

用大模型+AI自动识别网络威胁,帮安全团队高效处理海量日志。

Policy-Guided Threat Hunting: An LLM enabled Framework with Splunk SOC Triage

  • 融合大模型与强化学习,自动分析网络流量异常
  • 在真实与模拟数据上准确识别可疑攻击行为
  • 适合需要提升威胁检测效率的网络安全团队

面对不断演化的高级持续性威胁(APTs),传统安全方案已难以满足组织的威胁狩猎需求。同时,安全运营中心(SOC)分析师常因处理来自多种设备的海量日志而不堪重负。为此,我们提出一种自动化、动态的威胁狩猎框架,可适应网络环境变化,基于风险优先级对可疑和恶意流量进行处置。通过将代理式AI与成熟的SIEM平台Splunk集成,构建了从流量接入到异常评估的全流程框架:包括基于重构的自编码器进行异常检测,双层深度强化学习(DRL)实现初步分类,以及大语言模型(LLM)进行上下文分析。在公开基准数据集和模拟数据集上的实验表明,该框架能自主适应不同安全目标,有效识别恶意流量。框架显著提升了操作效率,支持分析师做出阻断、放行或监控等决策。本研究为安全决策提供了新范式,并推动了应对持续演化网络威胁的协同研究。

原文摘要 · Abstract (English)

With frequently evolving Advanced Persistent Threats (APTs) in cyberspace, traditional security solutions approaches have become inadequate for threat hunting for organizations. Moreover, SOC (Security Operation Centers) analysts are often overwhelmed and struggle to analyze the huge volume of logs received from diverse devices in organizations. To address these challenges, we propose an automated and dynamic threat hunting framework for monitoring evolving threats, adapting to changing network conditions, and performing risk-based prioritization for the mitigation of suspicious and malicious traffic. By integrating Agentic AI with Splunk, an established SIEM platform, we developed a unique threat hunting framework. The framework systematically and seamlessly integrates different threat hunting modules together, ranging from traffic ingestion to anomaly assessment using a reconstruction-based autoencoder, deep reinforcement learning (DRL) with two layers for initial triage, and a large language model (LLM) for contextual analysis. We evaluated the framework against a publicly available benchmark dataset, as well as against a simulated dataset. The experimental results show that the framework can effectively adapt to different SOC objectives autonomously and identify suspicious and malicious traffic. The framework enhances operational effectiveness by supporting SOC analysts in their decision-making to block, allow, or monitor network traffic. This study thus enhances cybersecurity and threat hunting literature by presenting the novel threat hunting framework for security decision-making, as well as promoting cumulative research efforts to develop more effective frameworks to battle continuously evolving cyber threats.

威胁狩猎大模型安全运营AI检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。