Skip to main navigation Skip to search Skip to main content

Harnessing Large Language Models for Automated Intrusion Detection Rule Generation in Cyber Range

  • Lei Du
  • , Jiarui Li
  • , Hao Yan
  • , Yuhan Chai
  • , Binxing Fang
  • , Zhaoquan Gu*
  • *Corresponding author for this work
  • School of Computer Science and Technology, Harbin Institute of Technology
  • Peng Cheng Laboratory
  • Guangzhou University

Research output: Contribution to journalArticlepeer-review

Abstract

Rule-based network intrusion detection systems hold great promise in cybersecurity due to their remarkable performance in identifying cyberattacks. Unfortunately, these detection rules are manually written by security experts for known attacks and are ineffective against unknown intrusion threats. Despite the progress made in existing work on automatic detection rule generation, the majority of such work focuses on synthesizing overly specific detection rules for input attack samples, neglecting the detection of these attack sample variants. Furthermore, most detection rule generation approaches rely on the content of the rule as an explanation, failing to provide a high-level understanding of both detection rules and attack samples. To tackle these challenges, we propose a novel detection rule generation framework, LLM4Rule, which aims to reproduce and automatically generate detection rules for discovered attacks in a cyber range without compromising real networks and endpoints. LLM4Rule leverages the knowledge reasoning capabilities of large language models (LLMs) to generate detection rules through interaction with LLMs, which consists of three components: preprocessing, detection rule generation, and attack sample mapping. The preprocessing component extracts and converts payloads from discovered attack samples. In the detection rule generation component, we propose a two-stage detection rule generation prompt approach that utilizes the self-correction ability of LLMs to filter invalid rules and enhances the generalization of valid rules to attack variants over the initially generated detection rules. Finally, the attack sample mapping component maps the attack samples to cybersecurity knowledge bases to help security operators better understand the generated detection rules and the attack samples. We conduct extensive experiments to demonstrate the effectiveness of LLM4Rule against four representative detection rule generation approaches on two datasets. The experimental results show that the detection rules generated by LLM4Rule can accurately detect cyberattack variants and effectively map attack samples to cybersecurity knowledge bases.

Original languageEnglish
Pages (from-to)12-20
Number of pages9
JournalIEEE Network
Volume39
Issue number5
DOIs
StatePublished - 2025
Externally publishedYes

Keywords

  • Network intrusion detection
  • detection rule generation
  • large language model

Fingerprint

Dive into the research topics of 'Harnessing Large Language Models for Automated Intrusion Detection Rule Generation in Cyber Range'. Together they form a unique fingerprint.

Cite this