MAD-LLM: A Novel Approach for Alert-Based Multi-stage Attack Detection via LLM

Dan Du, Xingmao Guan, Yuling Liu, Bo Jiang, Song Liu, Huamin Feng, Junrong Liu · 2024

In the realm of cybersecurity, detecting multi-stage attacks is vital for uncovering the actual intentions and strategies of attackers. However, the detection of multi-stage attacks is fraught with challenges due to the proliferation of alerts from diverse sources, the heterogeneity of their formats, and the weak correlations among them. This study explores MAD-LLM, a novel approach for alert-based multi-stage attack detection using Large Language Model (LLM). Leveraging their advanced natural language processing capabilities, LLM demonstrates significant advantages in text comprehension and pattern recognition. This research attempts to aggregate and correlate security alerts using the prompt engineering capabilities of LLM to reconstruct multi-stage attack chain. Experimental results indicate that LLM exhibit excellent performance in the task of multi-stage attack detection, providing an innovative solution for cybersecurity defense. This study also offers insights and implications for the application of LLM in other fields.

Read the paper · More papers on PaperTik