paper-with-me

홈 › Papers

GenTI: Benchmarking LLMs for Autonomous IDPS Rule Generation for Unseen Attacks

2026-06-04 · Hassan Jalil Hadi, Rehana Yasmin, Ali Shoker arxiv

Rule-based Intrusion Detection and Prevention Systems (IDPS) offer precise attack detection as well as mitigation, however their manually crafted, signature-driven rules limit adaptability to emerging and zero-day threats. Additionally, existing public datasets (e.g., CICIDS2017, UNSW-NB15) focus on traffic classification and provide little structured information to support automatic rule synthesis or prevention logic. To address this gap, we propose Generative Thread Intelligence (GenTI) \footnote{GenTI refers to the proposed framework, and GTI refers to the dataset.} an LLM-driven benchmark for automatic generation of IDPS rules targeting unseen attacks. The dataset (GTI) aggregates over 150k detection and prevention rules from Snort, Suricata, Emerging Threats, as well as 50k YARA, each annotated with protocol behavior, payload signatures, contextual relationships, mappings to Cyber Threat Intelligence (CTI), along with actionable response types (alert, drop, reject). Moreover, on top of this corpus we design an LLM-based pipeline that transforms analyst prompts and representative payloads into deployable rules via structured prompt engineering, Chain-of-Thought (CoT) reasoning, as well as a Chain-of-Verification (CoVe) loop for syntactic, semantic, and security validation. The generated rules are executed in real time on (Snort/Suricata) and evaluated by syntax accuracy, semantic similarity, CTI coverage, security effectiveness as well as unseen attacks detection. Furthermore, our GenTI instantiation achieves a composite rule-quality score of 89.4\%, with 94.8\% CTI coverage, improving unseen attacks detection from 45\% to 87.4\% and reducing the false-positive rate from 8.5\% to 2.3\%. Overall, GenTI establishes the first large-scale benchmark that tightly couples rule-level CTI with LLM-based automation, enabling adaptive, self-evolving IDPS.

📄 PDF Abstract BibTeX arXiv:2606.05844

Code (0)

등록된 구현이 없습니다.

Tasks

Semantic SimilarityIntrusion DetectionPrompt Engineering

Similar Papers 제목 키워드 기반

IDPS Signature Classification with a Reject Option and the Incorporation of Expert Knowledge

2022-07-19 · Hidetoshi Kawaguchi, Yuichi Nakatani, Shogo Okada

As the importance of intrusion detection and prevention systems (IDPSs) increases, great costs are incurred to manage the signatures that are generated by malicious communication pattern files. Experts in network securit…

Intrusion Detection

Scalable Agentic Reasoning for Designing Biologics Targeting Intrinsically Disordered Proteins

2025-12-17 · Matthew Sinclair, Moeen Meigooni, Archit Vasan, Ozan Gokdemir 외 arxiv

Intrinsically disordered proteins (IDPs) represent crucial therapeutic targets due to their significant role in disease -- approximately 80\% of cancer-related proteins contain long disordered regions -- but their lack o…

Drug Discovery

OdysseyArena: Benchmarking Large Language Models For Long-Horizon, Active and Inductive Interactions

2026-02-05 · Hang Yan, Fangzhi Xu, Qiushi Sun, Jinyang Wu 외 arxiv

The rapid advancement of Large Language Models (LLMs) has catalyzed the development of autonomous agents capable of navigating complex environments. However, existing evaluations primarily adopt a deductive paradigm, whe…

Argos: Agentic Time-Series Anomaly Detection with Autonomous Rule Generation via Large Language Models

2025-01-24 · Yile Gu, Yifan Xiong, Jonathan Mace, Yuting Jiang 외

Observability in cloud infrastructure is critical for service providers, driving the widespread adoption of anomaly detection systems for monitoring metrics. However, existing systems often struggle to simultaneously ach…

Anomaly DetectionTime SeriesTime Series Anomaly Detection

Project Auto-World: Towards Automated Benchmarking of Neural Relational Reasoners

2026-06-23 · Anirban Das, Joanne Boisson, Irtaza Khalid, Sumita Garai 외 arxiv

Reasoning about relational structures remains a significant challenge for neural models, particularly when they must systematically apply learned knowledge to problem instances that are harder than those seen in training…

Relational Reasoning