activity
20242026
collaborators

5 papers

cs.CR2026

Towards Small Language Models for Security Query Generation in SOC Workflows

Saleha Muzammil, Rahul Reddy, Vishal Kamalakrishnan +2

Analysts in Security Operations Centers routinely query massive telemetry streams using Kusto Query Language (KQL). Writing correct KQL requires specialized expertise, and this dep…

cs.CR2025

Rethinking Tamper-Evident Logging: A High-Performance, Co-Designed Auditing System

Rui Zhao, Muhammad Shoaib, Viet Tung Hoang +1

Existing tamper-evident logging systems suffer from high overhead and severe data loss in high-load settings, yet only provide coarse-grained tamper detection. Moreover, installing…

cs.CR2025

Are We There Yet? Unraveling the State-of-the-Art Graph Network Intrusion Detection Systems

Chenglong Wang, Pujia Zheng, Jiaping Gui +2

Network Intrusion Detection Systems (NIDS) are vital for ensuring enterprise security. Recently, Graph-based NIDS (GIDS) have attracted considerable attention because of their capa…

cs.CR2024

HADES: Detecting Active Directory Attacks via Whole Network Provenance Analytics

Qi Liu, Kaibin Bao, Wajih Ul Hassan +1

Due to its crucial role in identity and access management in modern enterprise networks, Active Directory (AD) is a top target of Advanced Persistence Threat (APT) actors. Conventi…

cs.CR2024

Accurate and Scalable Detection and Investigation of Cyber Persistence Threats

Qi Liu, Muhammad Shoaib, Mati Ur Rehman +3

In Advanced Persistent Threat (APT) attacks, achieving stealthy persistence within target systems is often crucial for an attacker's success. This persistence allows adversaries to…