3 papers
cs.CR2026
STAIR: Effective Incident Response Using an End-to-End Agentic Planning Framework
Hanlin Jiang, Jionghao Huang, Shaofei Li +6
Incident response planning is critical for restoring compromised software systems after cyberattacks. Common practice relies on expert-driven playbooks that encode fixed response p…
cs.CR2026
How Far Should We Need to Go : Evaluate Provenance-based Intrusion Detection Systems in Industrial Scenarios
Yue Xiao, Ling Jiang, Sen Nie +4
Provenance-based Intrusion Detection Systems (PIDSes) have been widely used to detect Advanced Persistent Threats (APTs). Although many studies achieve high performance in the eval…
cs.CR2025
KnowHow: Automatically Applying High-Level CTI Knowledge for Interpretable and Accurate Provenance Analysis
Yuhan Meng, Shaofei Li, Jiaping Gui +2
High-level natural language knowledge in CTI reports, such as the ATT&CK framework, is beneficial to counter APT attacks. However, how to automatically apply the high-level knowled…