Explainable Anomaly Detection in Network Traffic Using LLM
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F68407700%3A21240%2F25%3A00384334" target="_blank" >RIV/68407700:21240/25:00384334 - isvavai.cz</a>
Výsledek na webu
<a href="https://doi.org/10.1109/NOMS57970.2025.11073574" target="_blank" >https://doi.org/10.1109/NOMS57970.2025.11073574</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1109/NOMS57970.2025.11073574" target="_blank" >10.1109/NOMS57970.2025.11073574</a>
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
Explainable Anomaly Detection in Network Traffic Using LLM
Popis výsledku v původním jazyce
Network anomaly detection is essential for modern cybersecurity, yet existing systems often generate numerous alerts without clear explanations, leading to inefficiencies and high false-positive rates. This paper proposes a novel approach that integrates Large Language Models (LLMs) with an anomaly detection framework to enhance explainability in network traffic analysis. Instead of directly detecting anomalies, the LLM only interprets already flagged anomaly events, providing insights into their potential root causes. Our method reduces LLM over-usage while improving decision-making for security analysts. We evaluated our approach using real-world network traffic data, demonstrating its ability to enhance situational awareness, reduce false positives, and support more effective cybersecurity practices.
Název v anglickém jazyce
Explainable Anomaly Detection in Network Traffic Using LLM
Popis výsledku anglicky
Network anomaly detection is essential for modern cybersecurity, yet existing systems often generate numerous alerts without clear explanations, leading to inefficiencies and high false-positive rates. This paper proposes a novel approach that integrates Large Language Models (LLMs) with an anomaly detection framework to enhance explainability in network traffic analysis. Instead of directly detecting anomalies, the LLM only interprets already flagged anomaly events, providing insights into their potential root causes. Our method reduces LLM over-usage while improving decision-making for security analysts. We evaluated our approach using real-world network traffic data, demonstrating its ability to enhance situational awareness, reduce false positives, and support more effective cybersecurity practices.
Klasifikace
Druh
D - Stať ve sborníku
CEP obor
—
OECD FORD obor
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Návaznosti výsledku
Projekt
<a href="/cs/project/VJ02010024" target="_blank" >VJ02010024: Analýza šifrovaného provozu pomocí síťových toků</a><br>
Návaznosti
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Název statě ve sborníku
NOMS 2025-2025 IEEE Network Operations and Management Symposium
ISBN
979-8-3315-3163-8
ISSN
2374-9709
e-ISSN
—
Počet stran výsledku
6
Strana od-do
—
Název nakladatele
IEEE
Místo vydání
New York
Místo konání akce
Honolulu
Datum konání akce
12. 5. 2025
Typ akce podle státní příslušnosti
WRD - Celosvětová akce
Kód UT WoS článku
001556086900003