A Generative AI-Driven CTI Framework for IDS using Machine Learning and Knowledge Graph

Qazi Khalid Amin, Syed Hussain Ali Shah Gillani, Syed Nasir Mehmood Shah, Altaf Hussain · 2024

The rapid evolution of cyber-attacks has significantly increased the demand for improved cybersecurity defenses. Large enterprises are increasingly relying on various attack detection systems and cyber threat intelligence to detect attacks and introduce a robust strategy against malicious attacks. However, this also has its limitations i.e., cybersecurity professionals require a lot of time to analyze the attacks detected by an intrusion detection system (IDS) and generate appropriate reports. Therefore, we need to automate this process to improve efficiency. Generative AI plays a crucial role in generating efficient automated reports. Large Language Models (LLMs) in Generative AI, which can be tuned to complex datasets, have demonstrated their capabilities in various applications that use transformers such as image-to-text, text-to-image, and text generation. In this paper, we propose a Cyber Threat Intelligence (CTI)-based intrusion detection system (IDS) that combines honeypots, machine learning-based IDS, and LLMs in combination with a knowledge graph. Specifically, we use fine-tuned pre-trained models on custom datasets based on CVE information. This improves the system’s ability to detect threats and provide more in-depth analysis

Read the paper · More papers on PaperTik