Enhancing Log Analysis for Intrusion Detection Using Large Language Models
Diogo Fernandes Costa Silva, Arthur Ricardo Sousa Vitória, Rodrigo Z. Fanucchi, Arlindo Rodrigues Galvão Filho · 2025
Intrusion detection systems are critical for ensuring the security of modern networks, particularly in the face of increasingly sophisticated cyberattacks. Intrusion logs are inherently complex, containing vast amounts of detailed information about network activity. The sheer volume and granularity of this data often make it challenging for security analysts to interpret and extract actionable insights. To address this, we investigate the feasibility of using GPT-4o-mini to analyze and detect events within a dialogue-based framework. Within a few-shot scenario, leveraging GPT-4’s in-context learning capabilities, the pipeline eliminates the need for traditional machine learning techniques, such as model training and feature engineering, by directly utilizing the model’s ability to learn from minimal examples and infer patterns from the provided context. Qualitative results highlights that our proposed approach is promising to identify anomalies in network traffic, including unauthorized access attempts, DDoS attacks, and data infiltration events.