5 papers
AgentFlow: A Flow-Centric Policy Language and Framework for Securing LLM Agent Systems
Basavesh Ammanaghatta Shivakumar, Swarn Priya, Peng Gao
LLM agents increasingly read untrusted content, invoke external tools, access private data, and delegate work to other agents. Harm often arises not from a single unsafe action but…
CTIFoundry: An Agent-Native Corpus Scaffold for Cyber Threat Intelligence
Yutong Cheng, Changze Li, Qian Cui +4
Cyber threat intelligence (CTI) is increasingly consumed not by human analysts but by LLM agents that compose multi-step investigations at query time. The harness side of this shif…
eMicro: Real-Time Multi-Hop Access Control for Microservices with eBPF
Rizky Ramadhana Putra, Osama Bajaber, Saimon Amanuel Tsegai +4
Modern cloud applications often comprise thousands of microservices whose interactions form complex request paths. Traditional inter-service access control restricts individual ser…
TTPrint: Evidence-Grounded TTP Extraction via Diverge-then-Converge Verification
Yutong Cheng, Changze Li, Raihan Sultan Pasha Basuki +3
Extracting MITRE ATT&CK techniques from cyber threat intelligence (CTI) reports is an open-set, multi-label problem requiring both high recall (not missing techniques) and high pre…
CTINexus: Automatic Cyber Threat Intelligence Knowledge Graph Construction Using Large Language Models
Yutong Cheng, Osama Bajaber, Saimon Amanuel Tsegai +2
Textual descriptions in cyber threat intelligence (CTI) reports, such as security articles and news, are rich sources of knowledge about cyber threats, crucial for organizations to…