A Preliminary Study on an Intrusion Detection Method using Large Language Models in Industrial Control Systems
Smith Ann, Seong-je Cho, H. J. Kim · 2024
In recent studies, there has been a growing interest in leveraging large language models (LLMs) to detect cyber threats and intrusions. These models, designed with an intrinsic understanding of context, exhibit the capability to identify and address emerging threats, even in cases where they haven't been explicitly trained on them. In this paper, we embark on fundamental research aimed at detecting cyber intrusions within Industrial Control System (ICS) environments using LLMs. Initially, we gather diverse data from MITRE ATT&CK ICS framework (Adversarial Tactics, Techniques, and Common Knowledge for ICS framework), including tactics, techniques, and open datasets. Subsequently, we organize this data into a structured learning format based on the ATT&CK ICS matrix. This curated learning data serves as input for training an intrusion detection model utilizing LLMs.