conference-paper

On Automating Security Policies with Contemporary LLMs (Short Paper)

Research footprint

At a glance

الاستشهادات
4
المراجع
5
Comments
0
Paper overview

Abstract

The complexity of modern computing environments and the growing sophistication of cyber threats necessitate a more robust, adaptive, and automated approach to security enforcement. In this paper, we present a framework leveraging large language models (LLMs) for automating attack mitigation policy compliance through an innovative combination of in-context learning and retrieval-augmented generation (RAG). We begin by describing how our system collects and manages both tool and API specifications, storing them in a vector database to enable efficient retrieval of relevant information. We then detail the architectural pipeline that first decomposes high-level mitigation policies into discrete tasks and subsequently translates each task into a set of actionable API calls. Our empirical evaluation, conducted using publicly available CTI policies in STIXv2 format and Windows API documen-tation, demonstrates significant improvements in precision, recall, and Fl-score when employing RAG compared to a non-RAG baseline.

Record transparency

Publication details

DOI
10.1109/sse67621.2025.00018
OpenAlex
W4413361361
Document type
conference-paper
Language
EN
Last metadata update
المجتمع

Comments

تسجيل الدخول للانضمام إلى النقاش.

  1. لا توجد تعليقات بعد. ابدأ النقاش.