Abstract
Rule-based network intrusion detection systems hold great promise in cybersecurity due to their remarkable performance in identifying cyberattacks. Unfortunately, these detection rules are manually written by security experts for known attacks and are ineffective against unknown intrusion threats. Despite the progress made in existing work on automatic detection rule generation, the majority of such work focuses on synthesizing overly specific detection rules for input attack samples, neglecting the detection of these attack sample variants. Furthermore, most detection rule generation approaches rely on the content of the rule as an explanation, failing to provide a high-level understanding of both detection rules and attack samples. To tackle these challenges, we propose a novel detection rule generation framework, LLM4Rule, which aims to reproduce and automatically generate detection rules for discovered attacks in a cyber range without compromising real networks and endpoints. LLM4Rule leverages the knowledge reasoning capabilities of large language models (LLMs) to generate detection rules through interaction with LLMs, which consists of three components: preprocessing, detection rule generation, and attack sample mapping. The preprocessing component extracts and converts payloads from discovered attack samples. In the detection rule generation component, we propose a two-stage detection rule generation prompt approach that utilizes the self-correction ability of LLMs to filter invalid rules and enhances the generalization of valid rules to attack variants over the initially generated detection rules. Finally, the attack sample mapping component maps the attack samples to cybersecurity knowledge bases to help security operators better understand the generated detection rules and the attack samples. We conduct extensive experiments to demonstrate the effectiveness of LLM4Rule against four representative detection rule generation approaches on two datasets. The experimental results show that the detection rules generated by LLM4Rule can accurately detect cyberattack variants and effectively map attack samples to cybersecurity knowledge bases.
| Original language | English |
|---|---|
| Pages (from-to) | 12-20 |
| Number of pages | 9 |
| Journal | IEEE Network |
| Volume | 39 |
| Issue number | 5 |
| DOIs | |
| State | Published - 2025 |
| Externally published | Yes |
Keywords
- Network intrusion detection
- detection rule generation
- large language model
Fingerprint
Dive into the research topics of 'Harnessing Large Language Models for Automated Intrusion Detection Rule Generation in Cyber Range'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver