ATIRS: Towards Adaptive Threat Analysis with Intelligent Log Summarization and Response Recommendation
Daekyeong Park, Byeongjun Min, Sungwon Lim, Byeongjin Kim · Electronics · 2025
Modern maritime operations rely on diverse network components, increasing cybersecurity risks. While security solutions like Suricata generate extensive network alert logs, ships often operate without dedicated security personnel, requiring general crew members to review and respond to alerts. This challenge is exacerbated when vessels are at sea, delaying threat mitigation due to limited external support. We propose an Adaptive Threat Intelligence and Response Recommendation System (ATIRS), a small language model (SLM)-based framework that automates network alert log summarization and response recommendations to address this. The ATIRS processes real-world Suricata network alert log data and converts unstructured alerts into structured summaries, allowing the response recommendation model to generate contextually relevant and actionable countermeasures. It then suggests appropriate follow-up actions, such as IP blocking or account locking, ensuring timely and effective threat response. Additionally, the ATIRS employs adaptive learning, continuously refining its recommendations based on user feedback and emerging threats. Experimental results from shipboard network data demonstrate that the ATIRS significantly reduces the Mean Time to Respond (MTTR) while alleviating the burden on crew members, allowing for faster and more efficient threat mitigation, even in resource-constrained maritime environments.