Yuval Elovici

Senior Academic

LLMCloudHunter

Harnessing LLMs for Automated Extraction of Detection Rules from Cloud-Based CTI

Yuval Schwartz, Lavi Ben-Shimol, Dudu Mimran, Yuval Elovici,Asaf Shabtai

As the number and sophistication of cyber attacks have increased, threat hunting has become a critical aspect of active security, enabling proactive detection and mitigation of threats before they cause harm. Open-source cyber threat intelligence (OSCTI) is a valuable resource for threat hunters; however, it often comes in unstructured formats requiring manual analysis. Previous studies aimed at automating OSCTI analysis are limited since (1) they failed to provide actionable outputs, (2) they did not utilize images in OSCTI sources, and (3) they focused on on-premise environments, overlooking the growing importance of cloud security. To address these gaps, we propose LLMCloudHunter, a novel framework leveraging large language models (LLMs) to automatically generate generic-signature detection rule candidates from textual and visual OSCTI data. We evaluated the quality of the rules generated by our framework using 20 annotated real-world cloud threat reports. Results show that LLMCloudHunter achieved 83% precision and 99% recall for extracting API calls made by the threat actor and 99% precision with 97% recall for indicators of compromise (IoCs). Additionally, 99.18% of the generated detection rule candidates were successfully compiled and converted into Splunk queries.

Publication language English
Pages 1922-1941
Publication status Published - 28.04.2025

Keywords

Cloud
Cyber threat intelligence (CTI)
LLM
Sigma rules

ASJC Scopus subject areas

Information Systems and Management
Statistics, Probability and Uncertainty
Safety, Risk, Reliability and Quality
Modeling and Simulation
Artificial Intelligence
Computer Networks and Communications
Information Systems
Access to Document
10.1145/3696410.3714798
Other files and links
Link to publication in Scopus