liu.seSearch for publications in DiVA
1011121314151613 of 48
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • oxford
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Improving SIEM Rules through Transformer-Based Rule Evasion Detection and Attribution
Linköping University, Department of Computer and Information Science.
Linköping University, Department of Computer and Information Science.
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

Every day, security analysts investigate potential breaches in organizations’ digital infrastructure. Security Information and Event Management (SIEM) systems facilitate this by collecting and analysing security data in real time. Using analytics and automation, SIEMs help analysts detect threats and filter irrelevant information. At its core, SIEM systems rely on detection rules to analyse data. When a rule identifies a suspicious event, an alert is generated, drawing the attention of an analyst. These alerts form the basis of investigations, meaning that if an adversary evades a rule, a breach may go unnoticed.

To address this, we propose leveraging a transformer model to tokenize and embed executed PowerShell commands and PowerShell SIEM detection rules, enabling computation of cosine similarity between them. This allows for identification of evasions and determining which rules were evaded. Additionally, we introduce a regressor-based metamodel that selects the most suitable Large Language Model (LLM) from a pool and provides recommendations to improve rule coverage.

Using this approach, we found that at least 24% of the analysed rules in the 2025 SIGMA dataset were evadable. Our system detected 71% of hand-crafted evasions with a False Positive Rate (FPR) below 1% and correctly attributed 98% of the detected evasions to their corresponding detection rules, advancing the state-of-the-art system AMIDES. By selecting the most suitable LLM, the metamodel recommendations successfully updated 70% of the rules to detect previously unknown evasions. Additionally, security analysts, when presented with recommendations from our LLM-based metamodelling process reported that 31% of the recommendations could replace original rules with minor adjustments, while 47% offered key insights for manual refinement.

Place, publisher, year, edition, pages
2025. , p. 51
Keywords [en]
Security Information and Event Management (SIEM), Threat Detection, Detection Rule, PowerShell, Rule Evasion, Transformer, Command Embedding, Cosine Similarity, Metamodel, Random Forest (RF) Regressor, Large Language Model (LLM), Rule Improvement
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:liu:diva-220130ISRN: LIU-IDA/LITH-EX-A--25/114--SEOAI: oai:DiVA.org:liu-220130DiVA, id: diva2:2022128
External cooperation
Sectra Communications AB
Subject / course
Computer Engineering
Presentation
2025-11-11, Charles Babbage, 15:15 (English)
Supervisors
Examiners
Available from: 2026-01-09 Created: 2025-12-16 Last updated: 2026-01-09Bibliographically approved

Open Access in DiVA

fulltext(1441 kB)18 downloads
File information
File name FULLTEXT01.pdfFile size 1441 kBChecksum SHA-512
ac7698ebed7a0f9fedc4f8f982228220ccdc01e6975401482686a3c4ef10b5e6ad8e56b0a0650a09f6ce0d371f8178990d57660627891d3cdc561dff2ef202df
Type fulltextMimetype application/pdf

By organisation
Department of Computer and Information Science
Computer Systems

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 283 hits
1011121314151613 of 48
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • oxford
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf