Scholay

学术搜索 · AI 审稿 · LaTeX 协作

A LLM-based agent for the automatic generation and generalization of IDS rules

作者:Xiaowei Hu, Haoning Chen, Huaifeng Bao, Wen Wang, Feng Liu, Guoqiao Zhou, Peng Yin · 年份:2024 · DOI:10.1109/trustcom63139.2024.00259 · 被引用次数:5 · 研究领域:Digital Rights Management and Security、Multi-Agent Systems and Negotiation、Modeling, Simulation, and Optimization

Cyberattacks on digital services and Internet of Things (IoT) are rising, employing complex tactics. Using intrusion detection systems (IDS) to detect and counter threats at key network points is vital for strong cybersecurity. Traditional rule-based network IDS rely on predefined rules, which may not effectively recognize the myriad complex variants of potential attacks. AI-driven methods for detecting malicious traffic offer enhanced capabilities but can fall short in terms of interpretability and performance under high-throughput network conditions. To address these challenges, we propose a LLM-based (Large Language Model) agent that utilizes multiple sources inputs to generate and generalize rules. The generated rules are designed to detect a variety of corresponding malicious threats, while the generalized rules are crafted to identify similar variant attacks. We have amassed an extensive dataset, comprising vulnerability security reports, malicious traffic, and original IDS rules from authoritative sources, which serve as input for the LLM-based agent. Subsequently, comparative experiments were conducted to assess the performance of the new rules in detecting malicious traffic. The experimental results demonstrate the superior performance of these new rules across various metrics for malicious traffic detection.