arXiv:2606.10281cs.CRcs.CL2026-06被引 1

用新数据集测试大模型查日志的攻防能力,发现模型表现受设计影响大。

Benchmarking and Exploring the Capabilities of LLMs for Attack Investigations

  • 构建覆盖50种场景的日志基准数据集,测试大模型分析安全日志能力。
  • 五款前沿大模型在日志分析任务中表现差异显著,小模型错误率超60%。
  • 揭示模型解释质量与常见错误类型,指导安全团队合理使用大模型。

本文提出AuditBench,一个用于评估大语言模型(LLMs)在安全审计日志调查中能力的新基准数据集。该数据集包含来自Linux和Windows系统的审计日志,涵盖超过50种安全调查场景,包括恶意与良性活动。我们利用此基准评估了五款前沿大模型在四类典型安全事件响应任务中的表现,如警报分类、攻击链还原与持久化机制识别。分析显示,模型性能与错误模式随模型规模、数据表示方式、提示工程策略及具体任务类型而显著变化。同时,我们系统评估了模型生成解释的质量,并归纳出其在不同场景下的典型错误类型。本工作为评估大模型在安全日志分析中的能力提供了基础框架,为安全运营人员提供了实践洞见,并指明了未来研究方向。

原文摘要 · Abstract (English)

This paper presents AuditBench, a new benchmark dataset for evaluating the capabilities of LLMs at investigating security-related system audit logs. We design and use this benchmark to explore the performance of LLMs on four log-investigation tasks that incident response teams commonly perform, ranging from triaging alerts generated by detectors to identifying persistence mechanisms on compromised systems. AuditBench consists of system audit logs collected from Linux and Windows machines, and spans over 50 different security investigation scenarios, including both malicious and benign activity. Using our benchmark, we evaluate and analyze the performance of five frontier LLMs at analyzing audit logs for attack investigations. Our analysis illuminates how LLM performance and error profiles vary according to different design choices, such as differences in model size, data representation, prompt construction, and specific investigation tasks. Additionally, we characterize the quality of the explanations produced by LLMs and the types of errors that models make across our benchmark. Collectively, our work provides a foundation for assessing the capabilities of LLMs for investigating security logs, novel insights for practitioners using LLMs in security operations, and important directions for future research.

大模型日志分析安全检测审计日志

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。