liu.seSearch for publications in DiVA
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • oxford
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Improving SIEM Rules through Transformer-Based Rule Evasion Detection and Attribution
Linköpings universitet, Institutionen för datavetenskap.
Linköpings universitet, Institutionen för datavetenskap.
2025 (engelsk)Independent thesis Advanced level (degree of Master (Two Years)), 20 poäng / 30 hpOppgave
Abstract [en]

Every day, security analysts investigate potential breaches in organizations’ digital infrastructure. Security Information and Event Management (SIEM) systems facilitate this by collecting and analysing security data in real time. Using analytics and automation, SIEMs help analysts detect threats and filter irrelevant information. At its core, SIEM systems rely on detection rules to analyse data. When a rule identifies a suspicious event, an alert is generated, drawing the attention of an analyst. These alerts form the basis of investigations, meaning that if an adversary evades a rule, a breach may go unnoticed.

To address this, we propose leveraging a transformer model to tokenize and embed executed PowerShell commands and PowerShell SIEM detection rules, enabling computation of cosine similarity between them. This allows for identification of evasions and determining which rules were evaded. Additionally, we introduce a regressor-based metamodel that selects the most suitable Large Language Model (LLM) from a pool and provides recommendations to improve rule coverage.

Using this approach, we found that at least 24% of the analysed rules in the 2025 SIGMA dataset were evadable. Our system detected 71% of hand-crafted evasions with a False Positive Rate (FPR) below 1% and correctly attributed 98% of the detected evasions to their corresponding detection rules, advancing the state-of-the-art system AMIDES. By selecting the most suitable LLM, the metamodel recommendations successfully updated 70% of the rules to detect previously unknown evasions. Additionally, security analysts, when presented with recommendations from our LLM-based metamodelling process reported that 31% of the recommendations could replace original rules with minor adjustments, while 47% offered key insights for manual refinement.

sted, utgiver, år, opplag, sider
2025. , s. 51
Emneord [en]
Security Information and Event Management (SIEM), Threat Detection, Detection Rule, PowerShell, Rule Evasion, Transformer, Command Embedding, Cosine Similarity, Metamodel, Random Forest (RF) Regressor, Large Language Model (LLM), Rule Improvement
HSV kategori
Identifikatorer
URN: urn:nbn:se:liu:diva-220130ISRN: LIU-IDA/LITH-EX-A--25/114--SEOAI: oai:DiVA.org:liu-220130DiVA, id: diva2:2022128
Eksternt samarbeid
Sectra Communications AB
Fag / kurs
Computer Engineering
Presentation
2025-11-11, Charles Babbage, 15:15 (engelsk)
Veileder
Examiner
Tilgjengelig fra: 2026-01-09 Laget: 2025-12-16 Sist oppdatert: 2026-01-09bibliografisk kontrollert

Open Access i DiVA

fulltext(1441 kB)48 nedlastinger
Filinformasjon
Fil FULLTEXT01.pdfFilstørrelse 1441 kBChecksum SHA-512
ac7698ebed7a0f9fedc4f8f982228220ccdc01e6975401482686a3c4ef10b5e6ad8e56b0a0650a09f6ce0d371f8178990d57660627891d3cdc561dff2ef202df
Type fulltextMimetype application/pdf

Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar
Antall nedlastinger er summen av alle nedlastinger av alle fulltekster. Det kan for eksempel være tidligere versjoner som er ikke lenger tilgjengelige

urn-nbn

Altmetric

urn-nbn
Totalt: 1601 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • oxford
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf