13 papers
Find Before You Fine-Tune: A Diagnostic Study of Small LLMs for Cybersecurity QA
Shaswata Mitra, Subash Neupane, Trisha Chakraborty +4
Large Language Models (LLMs) are increasingly fine-tuned for critical-domain Question-Answering (QA), yet choosing which small model to adapt, before paying the cost of adaptation,…
FALCON: Transforming Cyber Threat Intelligence into Deployable IDS Rules with Self-Reflection
Shaswata Mitra, Subash Neupane, Martin Duclos +5
Signature-based Intrusion Detection Systems (IDS) detect malicious activity by matching network or host events against predefined rules. Security analysts manually develop these ru…
Agentra: A Supervisable Multi-Agent Framework for Enterprise Intrusion Response
Raj Patel, Shaswata Mitra, Michele Guida +3
Enterprise intrusion response still depends on static playbooks and analyst-driven triage, creating delay between alert generation and containment. We present Agentra, a supervisab…
Evaluating Open-Source LLMs for Multi-Label ATT&CK Technique Classification on CTI Reports
Ahmed Ryan, Saad Sakib Noor, Md Erfan +3
Classifying Cyber Threat Intelligence (CTI) using MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) is essential for proactive defense, but historically required…
On the Evaluation of Spiking Neural Network Configurations for Network Intrusion Detection
Raj Patel, David Amebley, Taye Akinrele +3
Network intrusion detection is a core component of modern cybersecurity infrastructure, yet the deep learning models that dominate the field are computationally demanding, motivati…
What Are Adversaries Doing? Automating Tactics, Techniques, and Procedures Extraction: A Systematic Review
Mahzabin Tamanna, Shaswata Mitra, Md Erfan +4
Adversaries continuously evolve their tactics, techniques, and procedures (TTPs) to achieve their objectives while evading detection, requiring defenders to continually update thei…