LATIDIA · Ciberseguridad
ORCAGen: Orquestación del engaño de malware consciente del contexto con IA generativa guiada por RAG
arXiv:2610.12415v1 Tipo de anuncio: nuevo Resumen: Las defensas contra malware a menudo eliminan o aíslan programas sospechosos lo más rápido posible. Si bien es efectivo para la contención, este enfoque también puede desperdiciar la oportunidad de observar
WhatsApp ↗Telegram ↗
La noticia
arXiv:2610.12415v1 Announce Type: new Abstract: Malware defenses often remove or isolate suspicious programs as quickly as possible. While effective for containment, this approach can also waste an opportunity to observe attacker behavior and deploy targeted countermeasures. ORCAGen takes a different approach: it uses GenAI to build malware-specific deception playbooks offline, validates them before deployment, and enforces only the verified logic at runtime. ORCAGen combines Retrieval-Augmented Generation (RAG) with structured prompt engineering to generate both proof-of-concept (PoC) malware and corresponding deception orchestration code. A curated knowledge base (KB) of malware procedures and active defense strategies grounds the generation process, helping the LLM produce threat-specific and executable deception logic rather than generic