11 papers
Just Testing, Move Along: Evasion of LLM-based System Log Interpretation by Prompt Injection
Max Landauer, Florian Skopik, Markus Wurzenberger +2
Large Language Models (LLMs) are increasingly integrated into Security Operations Center (SOC) workflows, where they support analysts in tasks such as the interpretation of system…
Beyond RAG for Cyber Threat Intelligence: A Systematic Evaluation of Graph-Based and Agentic Retrieval
Dzenan Hamzic, Florian Skopik, Max Landauer +2
Cyber threat intelligence (CTI) analysts must answer complex questions over large collections of narrative security reports. Retrieval-augmented generation (RAG) systems help langu…
CAM-LDS: Cyber Attack Manifestations for Automatic Interpretation of System Logs and Security Alerts
Max Landauer, Wolfgang Hotwagner, Thorina Boenke +2
Log data are essential for intrusion detection and forensic investigations. However, manual log analysis is tedious due to high data volumes, heterogeneous event formats, and unstr…
Resource-Aware Deployment Optimization for Collaborative Intrusion Detection in Layered Networks
André GarcÃa Gómez, Ines Rieger, Wolfgang Hotwagner +4
Collaborative Intrusion Detection Systems (CIDS) are increasingly adopted to counter cyberattacks, as their collaborative nature enables them to adapt to diverse scenarios across h…
AlertBERT: A noise-robust alert grouping framework for simultaneous cyber attacks
Lukas Karner, Max Landauer, Markus Wurzenberger +1
Automated detection of cyber attacks is a critical capability to counteract the growing volume and sophistication of cyber attacks. However, the high numbers of security alerts iss…
AttackMate: Realistic Emulation and Automation of Cyber Attack Scenarios Across the Kill Chain
Max Landauer, Wolfgang Hotwagner, Thorina Boenke +2
Adversary emulation tools facilitate scripting and automated execution of cyber attack chains, thereby reducing costs and manual expert effort required for security testing, cyber…