paper-with-me

홈 › Papers

Information-Dense Reasoning for Efficient and Auditable Security Alert Triage

2025-12-09 · Guangze Zhao, Yongzheng Zhang, Changbo Tian, Dan Xie, Hongri Liu, Bailing Wang arxiv

Security Operations Centers face massive, heterogeneous alert streams under minute-level service windows, creating the Alert Triage Latency Paradox: verbose reasoning chains ensure accuracy and compliance but incur prohibitive latency and token costs, while minimal chains sacrifice transparency and auditability. Existing solutions fail: signature systems are brittle, anomaly methods lack actionability, and fully cloud-hosted LLMs raise latency, cost, and privacy concerns. We propose AIDR, a hybrid cloud-edge framework that addresses this trade-off through constrained information-density optimization. The core innovation is gradient-based compression of reasoning chains to retain only decision-critical steps--minimal evidence sufficient to justify predictions while respecting token and latency budgets. We demonstrate that this approach preserves decision-relevant information while minimizing complexity. We construct compact datasets by distilling alerts into 3-5 high-information bullets (68% token reduction), train domain-specialized experts via LoRA, and deploy a cloud-edge architecture: a cloud LLM routes alerts to on-premises experts generating SOAR-ready JSON. Experiments demonstrate AIDR achieves higher accuracy and 40.6% latency reduction versus Chain-of-Thought, with robustness to data corruption and out-of-distribution generalization, enabling auditable and efficient SOC triage with full data residency compliance.

📄 PDF Abstract BibTeX arXiv:2512.08169

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

CORTEX: Collaborative LLM Agents for High-Stakes Alert Triage

2025-09-30 · Bowen Wei, Yuan Shen Tay, Howard Liu, Jinhao Pan 외 arxiv

Security Operations Centers (SOCs) are overwhelmed by tens of thousands of daily alerts, with only a small fraction corresponding to genuine attacks. This overload creates alert fatigue, leading to overlooked threats and…

NLLog: Lightweight, Explainable SOC Anomaly Detection via Log-to-Language Rewriting

2026-06-03 · Samuel Ndichu, Tao Ban, Seiichi Ozawa, Takeshi Takahashi 외 arxiv

System-generated logs underpin security monitoring, yet their rigid template-based format hinders both automated analysis and human comprehension. We present NLLog (Natural-Language Log), a lightweight pipeline that dete…

Anomaly Detection

Risk Averse Alert Prioritization for IDS Using Subnormal Gaussian Fuzzy Models

2026-05-26 · Murat Moran arxiv

Modern intrusion detection systems generate thousands of alerts daily, but alert fatigue severely limits security operations effectiveness due to too many false positives or low-impact events. We address this by proposin…

Intrusion Detection

Automated Alert Classification and Triage (AACT): An Intelligent System for the Prioritisation of Cybersecurity Alerts

2025-05-14 · Melissa Turcotte, François Labrèche, Serge-Olivier Paquette

Enterprise networks are growing ever larger with a rapidly expanding attack surface, increasing the volume of security alerts generated from security controls. Security Operations Centre (SOC) analysts triage these alert…

A Deep Belief Network Based Machine Learning System for Risky Host Detection

2017-12-29 · Wangyan Feng, Shuning Wu, Xiaodan Li, Kevin Kunkle

To assure cyber security of an enterprise, typically SIEM (Security Information and Event Management) system is in place to normalize security event from different preventive technologies and flag alerts. Analysts in the…

BIG-bench Machine LearningFeature EngineeringIntrusion DetectionManagement+1