3 papers
cs.CR2026
ARuleCon: Agentic Security Rule Conversion
Ming Xu, Hongtai Wang, Yanpei Guo +5
Security Information and Event Management (SIEM) systems make it possible for detecting intrusion anomalies in real-time manner by their applied security rules. However, the hetero…
cs.CR2025
ThreatPilot: Attack-Driven Threat Intelligence Extraction
Ming Xu, Hongtai Wang, Jiahao Liu +6
Efficient defense against dynamically evolving advanced persistent threats (APT) requires the structured threat intelligence feeds, such as techniques used. However, existing threa…
cs.CR2025
RulePilot: An LLM-Powered Agent for Security Rule Generation
Hongtai Wang, Ming Xu, Yanpei Guo +3
The real-time demand for system security leads to the detection rules becoming an integral part of the intrusion detection life-cycle. Rule-based detection often identifies malicio…