LLMCloudHunter: Harnessing LLMs for Automated Extraction of Detection Rules from Cloud-Based CTI
Yuval Schwartz, Lavi Benshimol, Dudu Mimran, Yuval Elovici, Asaf, Shabtai

TL;DR
This paper introduces LLMCloudHunter, a framework that uses large language models to automatically extract detection rules from unstructured cloud threat intelligence data, including text and images, improving threat detection in cloud environments.
Contribution
The paper presents a novel LLM-based framework that automates extraction of detection rules from unstructured OS-CTI data, including visual content, specifically for cloud security contexts.
Findings
Achieved 92% precision and 98% recall in extracting API calls.
Achieved 99% precision and 98% recall in extracting IoCs.
99.18% of generated rules were successfully converted into Splunk queries.
Abstract
As the number and sophistication of cyber attacks have increased, threat hunting has become a critical aspect of active security, enabling proactive detection and mitigation of threats before they cause significant harm. Open-source cyber threat intelligence (OS-CTI) is a valuable resource for threat hunters, however, it often comes in unstructured formats that require further manual analysis. Previous studies aimed at automating OSCTI analysis are limited since (1) they failed to provide actionable outputs, (2) they did not take advantage of images present in OSCTI sources, and (3) they focused on on-premises environments, overlooking the growing importance of cloud environments. To address these gaps, we propose LLMCloudHunter, a novel framework that leverages large language models (LLMs) to automatically generate generic-signature detection rule candidates from textual and visual…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsImage Processing and 3D Reconstruction · Data Quality and Management · Advanced Computational Techniques and Applications
