3 papers
cs.CR2026
Benchmarking and Exploring the Capabilities of LLMs for Attack Investigations
Aniket Anand, Yiwei Hou, Daniel Fields +4
This paper presents AuditBench, a new benchmark dataset for evaluating the capabilities of LLMs at investigating security-related system audit logs. We design and use this benchmar…
cs.CR2024
Facade: High-Precision Insider Threat Detection Using Deep Contextual Anomaly Detection
Alex Kantchelian, Casper Neo, Ryan Stevens +10
Insiders with privileged access have the power to cause great harm to their organization. Even a single insider threat incident can be catastrophic, resulting in both financial los…
cs.CR2024
Fine Grained Insider Risk Detection
Birkett Huber, Casper Neo, Keiran Sampson +3
We present a method to detect departures from business-justified workflows among support agents. Our goal is to assist auditors in identifying agent actions that cannot be explaine…