AIセキュリティポータル K Program
Towards Explainable Network Intrusion Detection using Large Language Models
Share
Abstract
Large Language Models (LLMs) have revolutionised natural language processing tasks, particularly as chat agents. However, their applicability to threat detection problems remains unclear. This paper examines the feasibility of employing LLMs as a Network Intrusion Detection System (NIDS), despite their high computational requirements, primarily for the sake of explainability. Furthermore, considerable resources have been invested in developing LLMs, and they may offer utility for NIDS. Current state-of-the-art NIDS rely on artificial benchmarking datasets, resulting in skewed performance when applied to real-world networking environments. Therefore, we compare the GPT-4 and LLama3 models against traditional architectures and transformer-based models to assess their ability to detect malicious NetFlows without depending on artificially skewed datasets, but solely on their vast pre-trained acquired knowledge. Our results reveal that, although LLMs struggle with precise attack detection, they hold significant potential for a path towards explainable NIDS. Our preliminary exploration shows that LLMs are unfit for the detection of Malicious NetFlows. Most promisingly, however, these exhibit significant potential as complementary agents in NIDS, particularly in providing explanations and aiding in threat response when integrated with Retrieval Augmented Generation (RAG) and function calling capabilities.
Benchmarking the Benchmark – Analysis of Synthetic NIDS Datasets
S. Layeghy, M. Gallagher, M. Portmann
Published: 2021
Explainable Intrusion Detection Systems (X-IDS): A Survey of Current Methods, Challenges, and Opportunities
Subash Neupane, Jesse Ables, William Anderson, Sudip Mittal, Shahram Rahimi, Ioana Banicescu, Maria Seale
Published: 2022.7.13
Large Language Models for Cyber Security: A Systematic Literature Review
Hanxiang Xu, Shenao Wang, Ningke Li, Kailong Wang, Yanjie Zhao, Kai Chen, Ting Yu, Yang Liu, Haoyu Wang
Published: 2024.5.8
NetFlow Datasets for Machine Learning-Based Network Intrusion Detection Systems
M. Sarhan, S. Layeghy, N. Moustafa, M. Portmann
Published: 2021
Towards a Standard Feature Set for Network Intrusion Detection System Datasets
M. Sarhan, S. Layeghy, M. Portmann
Published: 2022
Harnessing the Advanced Capabilities of LLM for Adaptive Intrusion Detection Systems
O. G. Lira, A. Marroquin, M. A. To
Published: 2024
Toward generating a new intrusion detection dataset and intrusion traffic characterization
Iman Sharafaldin, Arash Habibi Lashkari, Ali A Ghorbani
Published: 2018
FlowTransformer: A transformer framework for flow-based network intrusion detection systems
L. D. Manocchio, S. Layeghy, W. W. Lo, G. K. Kulatilleke, M. Sarhan, M. Portmann
Published: 2024
Revolutionizing Cyber Threat Detection with Large Language Models: A privacy-preserving BERT-based Lightweight Model for IoT/IIoT Devices
Mohamed Amine Ferrag, Mthandazo Ndhlovu, Norbert Tihanyi, Lucas C. Cordeiro, Merouane Debbah, Thierry Lestable, Narinderjit Singh Thandi
Published: 2023.6.26
CAN-BERT do it? Controller Area Network Intrusion Detection System based on BERT Language Model
N. Alkhatib, M. Mushtaq, H. Ghauch, J.-L. Danger
Published: 2022
Application of large language models to ddos attack detection
M. Guastalla, Y. Li, A. Hekmati, B. Krishnamachari
Published: 2023
Enhancing Intrusion Detection with Explainable AI: A Transparent Approach to Network Security
S. B. Mallampati, H. Seetha
Published: 2024
Deceiving Post-Hoc Explainable AI (XAI) Methods in Network Intrusion Detection
T. Senevirathna, B. Siniarski, M. Liyanage, S. Wang
Published: 2024
An Explainable AI-Based Intrusion Detection System for DNS Over HTTPS (DoH) Attacks
T. Zebin, S. Rezvy, Y. Luo
Published: 2022
XNIDS: Explaining Deep Learning-based Network Intrusion Detection Systems for Active Intrusion Responses
F. Wei, H. Li, Z. Zhao, H. Hu
Published: 2023
Orpo: Monolithic preference optimization without reference model
Hong, J., Lee, N., Thorne, J.
Published: 2024
Explainable Cross-domain Evaluation of ML-based Network Intrusion Detection Systems
S. Layeghy, M. Portmann
Published: 2023
DI-NIDS: Domain Invariant Network Intrusion Detection System
Siamak Layeghy, Mahsa Baktashmotlagh, Marius Portmann
Published: 2022.10.15
Network Intrusion Detection System in a Light Bulb
Liam Daly Manocchio, Siamak Layeghy, Marius Portmann
Published: 2022.10.7
Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks
Patrick Lewis, Ethan Perez, Aleksandra Piktus, Fabio Petroni, Vladimir Karpukhin, Naman Goyal, Heinrich Küttler, Mike Lewis, Wen-tau Yih, Tim Rocktäschel, Sebastian Riedel, Douwe Kiela
Published: 2020.5.23
Share