arXiv · 2407.13093
Using LLMs to Automate Threat Intelligence Analysis Workflows in Security Operation Centers
Abstract
SIEM systems are prevalent and play a critical role in a variety of analyst workflows in Security Operation Centers. However, modern SIEMs face a big challenge: they still cannot relieve analysts from the repetitive tasks involved in analyzing CTI (Cyber Threat Intelligence) reports written in natural languages. This project aims to develop an AI agent to replace the labor intensive repetitive tasks involved in analyzing CTI reports. The agent exploits the revolutionary capabilities of LLMs (e.g., GPT-4), but it does not require any human intervention.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
PeiYu Tseng, ZihDwo Yeh, Xushu Dai, Peng Liu. 2024-07-18. Using LLMs to Automate Threat Intelligence Analysis Workflows in Security Operation Centers. https://arxiv.org/abs/2407.13093
Cite the original work for its findings. Save a collection to share your selection of sources.