MENTOR: Malicious Network Traffic Detection Through Optimized LLM-Based Recognition
摘要
The rapid evolution of cyber threats necessitates the efficient detection of known and unknown encrypted malicious traffic data. Current detection approaches struggle with the cold start problem for unknown attacks, balancing detection accuracy with real-time performance and transfer capability. This paper presents MENTOR, a novel malicious network traffic detection framework that leverages optimized Large Language Models (LLMs) for enhanced detection ability. Through targeted fine-tuning strategies, MENTOR exploits LLMs’ semantic understanding and generalization abilities to process network traffic patterns. Experimental evaluation on multiple real-world datasets demonstrates MENTOR’s superior performance in identifying both known and emerging attack patterns compared to some SOTA approaches.