PulseAugur
实时 09:29:28
English(EN) From Threat Intelligence to Detection: Knowledge-driven Enrichment and Template-based Rule Grounding for Automated Sigma Rule Generation

新的AUTOSIGMA系统将网络威胁情报自动化生成为Sigma规则

研究人员开发了AUTOSIGMA,一个旨在将非结构化的网络威胁情报(CTI)转换为可操作的Sigma规则以进行威胁检测的自动化系统。该系统通过整合结构化知识库进行丰富,并利用LLM-as-a-Judge机制进行迭代验证,超越了仅依赖语言模型的方法,从而增强了规则生成能力。评估表明,在规则有效性、相关性、MITRE ATT&CK覆盖率和鲁棒性方面,AUTOSIGMA优于替代解决方案和独立的LLM。 AI

影响 自动化威胁检测规则的创建,可能提高网络安全响应的速度和准确性。

排序理由 该集群包含一篇学术论文,详细介绍了从网络威胁情报生成Sigma规则的新自动化系统。[lever_c_demoted from research: ic=1 ai=1.0]

在 arXiv cs.AI 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

新的AUTOSIGMA系统将网络威胁情报自动化生成为Sigma规则

报道来源 [1]

  1. arXiv cs.AI TIER_1 English(EN) · Sepehr Ghaffarzadegan, Boubakr Nour, Makan Pourzandi, Mourad Debbabi, Chadi Assi ·

    从威胁情报到检测:知识驱动的丰富化和基于模板的规则基础,用于自动化Sigma规则生成

    arXiv:2608.19011v1 Announce Type: cross Abstract: Mechanisms for dynamically converting cyber threat intelligence (CTI) into actionable detection capabilities are necessary due to the rapid evolution of Advanced Persistent Threats (APTs). Sigma rules are an essential part of cont…