LATIDIA · Ciberseguridad
CyberClear: un punto de referencia para los sistemas de agentes LLM en la procedencia de la cadena de ataques APT
arXiv: 2609.32424v1Tipo de anuncio: nuevo Resumen: Los agentes del modelo de lenguaje grande han demostrado capacidades prometedoras en tareas de ciberseguridad, pero su capacidad para reconstruir la CAM de ataque de amenaza persistente avanzada completa
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.32424v1 Announce Type: new Abstract: Large language model agents have demonstrated promising capabilities in cybersecurity tasks, yet their ability to reconstruct complete Advanced Persistent Threat attack campaigns from complex security logs remains largely unexplored. Existing cybersecurity benchmarks for agents mainly focus on vulnerability discovery, exploitation, and security analysis tasks, leaving the evaluation of attack chain provenance under realistic security logs insufficiently studied. To address this gap, we introduce CyberClear, a benchmark for evaluating LLM agents and advanced agent systems on APT attack chain provenance from long-context security logs. CyberClear covers both single-step attacks and multi-stage attack chains, requiring agents to identify attack evidence, infer attack progression, and generate provenance graphs