From the 1 of 5 linked papers with an AI index.
5 papers
(EC)2: Event-Centric Explainability for Cybersecurity Through Multi-Agent LLM Investigations
Neta Kirmayer, David Tayouri, Andrés Murillo +3
The paper presents (EC)2, a multi‑agent framework that uses large language models to generate event‑centric, hypothesis‑driven explanations for cybersecurity alerts, improving anal…
COHORT: Collaborative Orchestration for Hardening via Offensive Replay on Emulated Topologies
Chen Frydman, Aviram Zilberman, Rubin Krief +6
Mitigating an observed adversary in an enterprise network typically takes weeks of expert work: an analyst derives a mitigation tailored to that adversary, validates it without bre…
SCyTAG: Scalable Cyber-Twin for Threat-Assessment Based on Attack Graphs
David Tayouri, Elad Duani, Abed Showgan +8
Understanding the risks associated with an enterprise environment is the first step toward improving its security. Organizations employ various methods to assess and prioritize the…
GeNet: A Multimodal LLM-Based Co-Pilot for Network Topology and Configuration
Beni Ifland, Elad Duani, Rubin Krief +9
Communication network engineering in enterprise environments is traditionally a complex, time-consuming, and error-prone manual process. Most research on network engineering automa…
Labeling NIDS Rules with MITRE ATT&CK Techniques: Machine Learning vs. Large Language Models
Nir Daniel, Florian Klaus Kaiser, Shay Giladi +6
Analysts in Security Operations Centers (SOCs) are often occupied with time-consuming investigations of alerts from Network Intrusion Detection Systems (NIDS). Many NIDS rules lack…