Skip to main navigation Skip to search Skip to main content

SecFort: An LLM-Driven Unified Framework for Enterprise-Level Traffic Attack Detection

  • Wenying Feng
  • , Yujia Shi
  • , Angxiao Zhao
  • , Aiting Yao
  • , Ruonan Li
  • , Zhaoquan Gu*
  • *Corresponding author for this work
  • Department of New Networks
  • Harbin Institute of Technology

Research output: Contribution to journalConference articlepeer-review

Abstract

Enterprise-level protection against network attacks has matured into a multi-layered stack of firewalls, IDS (Intrusion Detection Systems) and endpoint-detection platforms. Academic research in the past decade has successively introduced statistical learning based neural networks and large language models to detect threats and attacks. However, practitioners still use signature-based blacklists and manually tuned heuristics in practice, advanced models rarely work in realistic high-speed networks. First, existing solutions are inherently point-wise: each appliance independently emits alerts without an end-to-end workflow that unifies collection, analyzing, reasoning and response. Second, statistically motivated models - although theoretically elegant - demand voluminous, high-quality ground truth that is either privacy-prohibited or expert-dependent, thus impractical to curate at enterprise scale. Faced with these challenges, we propose SecFort, a holistic, LLM (Large Language Model)-based framework that integrates three collaborative modules: (i) BinFlow for malicious traffic screening, (ii) MultiStrike for granular attack-type identification, and (iii) PayLens for microscopic analysis of attack behavior from payloads. Extensive evaluations on real-world collected attack traffic and payload datasets demonstrate the effectiveness of SecFort. Compared with manual alert-by-alert inspection, this pipeline significantly accelerates security analytics and reduces the operational cost of enterprise-level protection.

Original languageEnglish
Pages (from-to)2194-2199
Number of pages6
JournalProceedings of the International Conference on Computer Supported Cooperative Work in Design, CSCWD
Issue number2026
DOIs
StatePublished - 2026
Externally publishedYes
Event29th International Conference on Computer Supported Cooperative Work in Design, CSCWD 2026 - Fuzhou, China
Duration: 13 May 202615 May 2026

Keywords

  • Traffic classification
  • attack detection
  • large language model

Fingerprint

Dive into the research topics of 'SecFort: An LLM-Driven Unified Framework for Enterprise-Level Traffic Attack Detection'. Together they form a unique fingerprint.

Cite this