10 papers
Holoscope: Open and Lightweight Telescope & Honeypot Platform
Andrea Sordello, Marco Mellia, Idilio Drago +7
The complexity and scale of Internet attacks call for distributed, cooperative observatories capable of monitoring malicious traffic across diverse networks. Holoscope is an open,…
Dense Contexts Are Hard Contexts: Lexical Density Limits Effective Context in LLMs
Giovanni Dettori, Matteo Boffa, Danilo Giordano +2
Input length and the position of relevant information are widely cited as the primary causes of degraded LLM long-context performance. Here, we study lexical density -- the rate at…
Improving Generalization on Cybersecurity Tasks with Multi-Modal Contrastive Learning
Jianan Huang, Rodolfo V. Valentim, Luca Vassio +4
The use of ML in cybersecurity has long been impaired by generalization issues: Models that work well in controlled scenarios fail to maintain performance in production. The root c…
Towards Agentic Honeynet Configuration
Federico Mirra, Matteo Boffa, Idilio Drago +2
Honeypots are deception systems that emulate vulnerable services to collect threat intelligence. While deploying many honeypots increases the opportunity to observe attacker behavi…
CyberSleuth: Autonomous Blue-Team LLM Agent for Web Attack Forensics
Stefano Fumero, Kai Huang, Matteo Boffa +3
Post-mortem analysis of compromised systems is a key aspect of cyber forensics, today a mostly manual, slow, and error-prone task. Agentic AI, i.e., LLM-powered agents, is a promis…
The Potential of Erroneous Outbound Traffic Analysis to Unveil Silent Internal Anomalies
Andrea Sordello, Zhihao Wang, Kai Huang +2
Passive measurement has traditionally focused on inbound traffic to detect malicious activity, based on the assumption that threats originate externally. In this paper, we offer a…