Abstract
Enterprise-level protection against network attacks has matured into a multi-layered stack of firewalls, IDS (Intrusion Detection Systems) and endpoint-detection platforms. Academic research in the past decade has successively introduced statistical learning based neural networks and large language models to detect threats and attacks. However, practitioners still use signature-based blacklists and manually tuned heuristics in practice, advanced models rarely work in realistic high-speed networks. First, existing solutions are inherently point-wise: each appliance independently emits alerts without an end-to-end workflow that unifies collection, analyzing, reasoning and response. Second, statistically motivated models - although theoretically elegant - demand voluminous, high-quality ground truth that is either privacy-prohibited or expert-dependent, thus impractical to curate at enterprise scale. Faced with these challenges, we propose SecFort, a holistic, LLM (Large Language Model)-based framework that integrates three collaborative modules: (i) BinFlow for malicious traffic screening, (ii) MultiStrike for granular attack-type identification, and (iii) PayLens for microscopic analysis of attack behavior from payloads. Extensive evaluations on real-world collected attack traffic and payload datasets demonstrate the effectiveness of SecFort. Compared with manual alert-by-alert inspection, this pipeline significantly accelerates security analytics and reduces the operational cost of enterprise-level protection.
| Original language | English |
|---|---|
| Pages (from-to) | 2194-2199 |
| Number of pages | 6 |
| Journal | Proceedings of the International Conference on Computer Supported Cooperative Work in Design, CSCWD |
| Issue number | 2026 |
| DOIs | |
| State | Published - 2026 |
| Externally published | Yes |
| Event | 29th International Conference on Computer Supported Cooperative Work in Design, CSCWD 2026 - Fuzhou, China Duration: 13 May 2026 → 15 May 2026 |
Keywords
- Traffic classification
- attack detection
- large language model
Fingerprint
Dive into the research topics of 'SecFort: An LLM-Driven Unified Framework for Enterprise-Level Traffic Attack Detection'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver