LATIDIA · Ciberseguridad
Conozca lo normal, rastree el ataque: investigación de LLM basada en el contexto y con estado sobre la procedencia del sistema
arXiv:2609.36494v1 Anuncio Tipo: nuevo Resumen: Los sistemas de detección de intrusiones basados en procedencia (PIDS) identifican actividad sospechosa en flujos de auditoría, pero sus resultados siguen siendo difíciles de convertir en narrativas de ataque coherentes.
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.36494v1 Announce Type: new Abstract: Provenance-based intrusion detection systems (PIDSs) identify suspicious activity in audit streams, but their outputs remain difficult to turn into coherent attack narratives. Direct LLM analyses of local anomalous subgraphs lack deployment-specific normal-behavior knowledge and validated attack state across evidence fragments. This can cause unsupported attack interpretations of routine activities and incorrect attribution of temporally dispersed evidence to attack stages. We present ANCHOR, an investigation-oriented provenance system that combines evidence curation with context-grounded LLM reasoning. It calibrates anomaly judgments by relation type and links anomalous windows through rare relation-role patterns. The resulting evidence queues preserve causal structure, temporal boundaries, and cross-window continuity. The investigator interprets process-centered