TY - GEN
T1 - SecKQL-Agent
T2 - 31st International Conference on Database Systems for Advanced Applications, DASFAA 2026
AU - Zhang, Huan
AU - Wang, Haiyan
AU - Long, Shaofang
AU - Tan, Hao
AU - Wang, Ziyu
AU - Jia, Yan
AU - Gu, Zhaoquan
N1 - Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd. 2026.
PY - 2026
Y1 - 2026
N2 - Text-to-query language (Text-to-QL) techniques allow analysts to express complex threat-hunting and investigation intents in natural language, lowering the barrier to large-scale security telemetry and facilitating practical security analytics. Yet, despite this potential, public resources for this domain remain scarce due to the technical complexities involved in handling wide-column, semi-structured, and high-volume security datasets. To fill this gap, we construct SecKQL-APT29, a Kusto Query Language (KQL) benchmark derived from real APT29 attack traces. It offers an executable, structured schema and expert-annotated Text-to-KQL pairs. We also propose SecKQL-Agent, a Text-to-KQL framework tailored for security analytics that addresses limitations of directly applying Text-to-SQL methods: (i) redundant and oversized schemas, (ii) limited domain adaptation to security query languages, and (iii) semantic mismatch between generated queries and user intent. SecKQL-Agent comprises three components: a Hybrid-attention Schema Refiner for relevant and compact schema selection; an Adaptive Few-shot Generator for robust query generation; and a Chain-of-Thought (CoT)-driven Semantic Consistency Reflector for result-aware semantic validation. Experiments on two benchmarks against three representative baselines show that SecKQL-Agent achieves an optimal balance between execution accuracy and computational efficiency, demonstrating its effectiveness and generalizability.
AB - Text-to-query language (Text-to-QL) techniques allow analysts to express complex threat-hunting and investigation intents in natural language, lowering the barrier to large-scale security telemetry and facilitating practical security analytics. Yet, despite this potential, public resources for this domain remain scarce due to the technical complexities involved in handling wide-column, semi-structured, and high-volume security datasets. To fill this gap, we construct SecKQL-APT29, a Kusto Query Language (KQL) benchmark derived from real APT29 attack traces. It offers an executable, structured schema and expert-annotated Text-to-KQL pairs. We also propose SecKQL-Agent, a Text-to-KQL framework tailored for security analytics that addresses limitations of directly applying Text-to-SQL methods: (i) redundant and oversized schemas, (ii) limited domain adaptation to security query languages, and (iii) semantic mismatch between generated queries and user intent. SecKQL-Agent comprises three components: a Hybrid-attention Schema Refiner for relevant and compact schema selection; an Adaptive Few-shot Generator for robust query generation; and a Chain-of-Thought (CoT)-driven Semantic Consistency Reflector for result-aware semantic validation. Experiments on two benchmarks against three representative baselines show that SecKQL-Agent achieves an optimal balance between execution accuracy and computational efficiency, demonstrating its effectiveness and generalizability.
KW - Cybersecurity Analytics
KW - Kusto Query Language (KQL)
KW - LLM-based Agent
KW - Text-to-Query Generation
UR - https://www.scopus.com/pages/publications/105040349595
U2 - 10.1007/978-981-92-0378-9_17
DO - 10.1007/978-981-92-0378-9_17
M3 - 会议稿件
AN - SCOPUS:105040349595
SN - 9789819203772
T3 - Lecture Notes in Computer Science
SP - 272
EP - 288
BT - Database Systems for Advanced Applications - 31st International Conference, DASFAA 2026, Proceedings
A2 - Jung, Hyungsoo
A2 - Wang, Tianzheng
A2 - Toyoda, Masashi
A2 - Kwon, Hyuk-Yoon
A2 - Lee, Jae-woong
PB - Springer Science and Business Media Deutschland GmbH
Y2 - 27 April 2026 through 30 April 2026
ER -