5 papers
Towards Agentic Investigation of Security Alerts
Even Eilertsen, Vasileios Mavroeidis, Gudmund Grov
Security analysts are overwhelmed by the volume of alerts and the low context provided by many detection systems. Early-stage investigations typically require manual correlation ac…
A Graph-Based Approach to Alert Contextualisation in Security Operations Centres
Magnus Wiik Eckhoff, Peter Marius Flydal, Siem Peters +4
Interpreting the massive volume of security alerts is a significant challenge in Security Operations Centres (SOCs). Effective contextualisation is important, enabling quick distin…
I Know Which LLM Wrote Your Code Last Summer: LLM generated Code Stylometry for Authorship Attribution
Tamas Bisztray, Bilel Cherif, Richard A. Dubniczky +6
Detecting AI-generated code, deepfakes, and other synthetic content is an emerging research challenge. As code generated by Large Language Models (LLMs) becomes more common, identi…
LLM-Powered Intent-Based Categorization of Phishing Emails
Even Eilertsen, Vasileios Mavroeidis, Gudmund Grov
Phishing attacks remain a significant threat to modern cybersecurity, as they successfully deceive both humans and the defense mechanisms intended to protect them. Traditional dete…
On the use of neurosymbolic AI for defending against cyber attacks
Gudmund Grov, Jonas Halvorsen, Magnus Wiik Eckhoff +3
It is generally accepted that all cyber attacks cannot be prevented, creating a need for the ability to detect and respond to cyber attacks. Both connectionist and symbolic AI are…