The increasing complexity and volume of cybersecurity alerts significantly challenge threat detection efforts, particularly within Security Operations Centers (SOCs), where the high rate of false positives is usually observed. This burden not only strains resources but also increases the risk of overlooking genuine security breaches. Leveraging advanced machine learning (ML) techniques, particularly Large Language Models (LLMs), this paper introduces a novel methodology aimed at enhancing the precision of alert classifications from Windows endpoints’ security logs. Notably, we extracted approximately 700 false and real threat cases from a real enterprise network. The proposed approach involves creating an “Execution Graph” for each alerting Windows process, which is then processed by a “Graph Contextualizer” block. This block transforms complex process interactions into structured, analyzable formats suitable for training and inference in LLMs. The transformed data objects are subsequently fed into several locally fine-tuned LLMs designed to classify the alerts accurately. The preliminary evaluation of this pipeline achieves high levels of precision and recall, thus substantiating the effectiveness of the proposed approach. The methodology improves the operational efficiency of SOCs by reducing the investigative overhead of false threats and assisting in the detection of real threats, offering a scalable pipeline to integrate into existing security infrastructures.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Leveraging Large Language Models for Reducing False Positives and Prioritizing Alerts in Intrusion Detection Systems

  • Ali Mustafa,
  • Fouad Trad,
  • Ali Chehab

摘要

The increasing complexity and volume of cybersecurity alerts significantly challenge threat detection efforts, particularly within Security Operations Centers (SOCs), where the high rate of false positives is usually observed. This burden not only strains resources but also increases the risk of overlooking genuine security breaches. Leveraging advanced machine learning (ML) techniques, particularly Large Language Models (LLMs), this paper introduces a novel methodology aimed at enhancing the precision of alert classifications from Windows endpoints’ security logs. Notably, we extracted approximately 700 false and real threat cases from a real enterprise network. The proposed approach involves creating an “Execution Graph” for each alerting Windows process, which is then processed by a “Graph Contextualizer” block. This block transforms complex process interactions into structured, analyzable formats suitable for training and inference in LLMs. The transformed data objects are subsequently fed into several locally fine-tuned LLMs designed to classify the alerts accurately. The preliminary evaluation of this pipeline achieves high levels of precision and recall, thus substantiating the effectiveness of the proposed approach. The methodology improves the operational efficiency of SOCs by reducing the investigative overhead of false threats and assisting in the detection of real threats, offering a scalable pipeline to integrate into existing security infrastructures.