<p>The increasing complexity and frequency of cyber-attacks, particularly advanced persistent threats (APTs), reveal the significant limitations of existing security mechanisms. As adversaries leverage artificial intelligence (AI) and substantial resources, their tactics have become more organized and potent, allowing them to consistently evade conventional detection. To address this critical security gap, we propose a novel machine learning (ML)-based framework for high-fidelity threat detection. This task is challenged by high-volume, high-velocity Linux system telemetry, which necessitates the real-time processing and massive parallelization inherent to high-performance computing (HPC) infrastructure. This solution utilizes a range of learning algorithms, including RF, feedforward neural networks (FNN), and convolutional neural networks (CNN), to accurately detect and predict sophisticated malicious activities, including zero-day exploits. A key innovation of our system is the integration of a large language model (LLM) as a post-detection analytical module. The LLM does not perform classification but is used exclusively to generate detailed, human-readable descriptions and contextual explanations for threats already identified with high confidence by the ML models, requires significant distributed computing resources to generate detailed and human-readable descriptions of the identified threats. This synergy empowers the defenders with the contextual understanding needed to develop effective countermeasures. We validated our approach on a novel, custom-generated dataset built from simulating advanced, multi-stage attacks. The results demonstrate the superior efficacy of the framework, achieving precision of 97% and 99% recall, thus providing a robust and insightful solution for modern cyber defense investigations.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

L2DAPT – LLMs and Linux: decoding advanced persistent threats

  • Syed Sohaib Karim,
  • Mehreen Afzal,
  • Waseem Iqbal,
  • Farooq Zaman,
  • Imran Rashid

摘要

The increasing complexity and frequency of cyber-attacks, particularly advanced persistent threats (APTs), reveal the significant limitations of existing security mechanisms. As adversaries leverage artificial intelligence (AI) and substantial resources, their tactics have become more organized and potent, allowing them to consistently evade conventional detection. To address this critical security gap, we propose a novel machine learning (ML)-based framework for high-fidelity threat detection. This task is challenged by high-volume, high-velocity Linux system telemetry, which necessitates the real-time processing and massive parallelization inherent to high-performance computing (HPC) infrastructure. This solution utilizes a range of learning algorithms, including RF, feedforward neural networks (FNN), and convolutional neural networks (CNN), to accurately detect and predict sophisticated malicious activities, including zero-day exploits. A key innovation of our system is the integration of a large language model (LLM) as a post-detection analytical module. The LLM does not perform classification but is used exclusively to generate detailed, human-readable descriptions and contextual explanations for threats already identified with high confidence by the ML models, requires significant distributed computing resources to generate detailed and human-readable descriptions of the identified threats. This synergy empowers the defenders with the contextual understanding needed to develop effective countermeasures. We validated our approach on a novel, custom-generated dataset built from simulating advanced, multi-stage attacks. The results demonstrate the superior efficacy of the framework, achieving precision of 97% and 99% recall, thus providing a robust and insightful solution for modern cyber defense investigations.