paper

ChatIDS: Advancing Explainable Cybersecurity Using Generative AI

arXiv:2306.14504

Abstract

Intrusion Detection Systems (IDS) are a proven approach to secure networks. Network-based IDS are typically installed on routers or Internet gateways. This allows them to inspect any incoming or outgoing network traffic, to compare the signatures of network packets with a database of suspicious signatures, or to use artificial intelligence. If the IDS identifies a network connection as suspicious, it sends an alert to the respective user. However, in a privately used network, it is difficult for users without cybersecurity expertise to understand IDS alerts, to distinguish cyberattacks from false alarms, and to respond in time with adequate measures. This puts the security of home networks, smart home installations, home-office workers, etc. at risk, even if an IDS is correctly installed and configured. In this work, we propose ChatIDS, our approach to explain IDS alerts to non-experts by using large language models. We evaluate the feasibility of ChatIDS by using ChatGPT, and we identify open research issues with the help of interdisciplinary experts in artificial intelligence. Our results show that ChatIDS has the potential to increase network security by proposing meaningful security measures in an intuitive language from IDS alerts. Nevertheless, some potential issues in areas such as trust, privacy, ethics, etc. need to be resolved, before ChatIDS might be put into practice.

Published by ThinkMind on https://www.thinkmind.org/library/Sec/Sec_v17_n12_2024/sec_v17_n12_2024_6.html

ChatIDS: Advancing Explainable Cybersecurity Using Generative AI · wovepaper