<p>Cybersecurity and artificial intelligence (AI) increasingly intersect as organizations grapple with sophisticated cyber threats and expanding digital landscapes. Incident response teams traditionally rely on structured procedures to identify, manage, and mitigate cyber incidents. Our work explores the effectiveness of generative AI, specifically Large Language Models (LLMs), within cybersecurity, focusing primarily on incident response processes. Experimental evaluations demonstrate that specific LLMs exhibit distinct strengths suitable for different stages of incident management. GPT-4o and GPT-3.5 show high clarity, consistency and coherence, making them appropriate for real-time containment, isolation, eradication and recovery tasks. Conversely, models such as GPT-o1 and GPT-4 offer superior reasoning capabilities and conciseness, better supporting incident preparation, post-incident analysis, vulnerability assessment and training development. Key limitations pertaining to current LLM implementations are identified, particularly token context constraints in addition to a discussion about ethical considerations regarding reliance on AI responses, including potential impacts on workforce skills and organizational security posture.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Analysing the role of LLMs in cybersecurity incident management

  • Gavin Jones,
  • Dimitrios Kasimatis,
  • Nikolaos Pitropakis,
  • Richard Macfarlane,
  • William J. Buchanan

摘要

Cybersecurity and artificial intelligence (AI) increasingly intersect as organizations grapple with sophisticated cyber threats and expanding digital landscapes. Incident response teams traditionally rely on structured procedures to identify, manage, and mitigate cyber incidents. Our work explores the effectiveness of generative AI, specifically Large Language Models (LLMs), within cybersecurity, focusing primarily on incident response processes. Experimental evaluations demonstrate that specific LLMs exhibit distinct strengths suitable for different stages of incident management. GPT-4o and GPT-3.5 show high clarity, consistency and coherence, making them appropriate for real-time containment, isolation, eradication and recovery tasks. Conversely, models such as GPT-o1 and GPT-4 offer superior reasoning capabilities and conciseness, better supporting incident preparation, post-incident analysis, vulnerability assessment and training development. Key limitations pertaining to current LLM implementations are identified, particularly token context constraints in addition to a discussion about ethical considerations regarding reliance on AI responses, including potential impacts on workforce skills and organizational security posture.