arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

从威胁情报到检测:知识驱动的丰富化与基于模板的规则落地用于自动化Sigma规则生成

From Threat Intelligence to Detection: Knowledge-driven Enrichment and Template-based Rule Grounding for Automated Sigma Rule Generation

Sepehr Ghaffarzadegan, Boubakr Nour, Makan Pourzandi, Mourad Debbabi, Chadi Assi

arXiv 2608.19011首次发表:更新:

发表机构

Concordia University; Ericsson Research(康考迪亚大学; 爱立信研究院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究设计了AUTOSIGMA,结合知识驱动丰富化等技术,将非结构化CTI报告自动生成Sigma规则,其在多项指标上优于其他方案。

AI 中文摘要

由于高级持续性威胁(APT)的快速演变,需要将网络威胁情报(CTI)动态转换为可执行检测能力的机制。Sigma规则是当代威胁检测工作流的重要组成部分,因为它们提供了一个平台无关的框架,用于表达检测逻辑,可转换为SIEM系统中的特定查询。手动编写Sigma规则的传统技术容易出错,且需要广泛的知识,这限制了其可扩展性。尽管存在开源和行业维护的Sigma规则存储库,但它们往往跟不上新兴威胁的步伐,且需要频繁定制以适应不同的操作环境。这凸显了动态规则生成的必要性,该生成需适应不断演变的攻击技术以及特定用例。在本研究中,我们设计了AUTOSIGMA,这是一种将非结构化CTI报告转换为相关Sigma规则的自动化解决方案。AUTOSIGMA并非仅依赖语言模型,而是利用结构化知识库丰富部分输入,将丰富后的内容与现有Sigma规则存储库进行匹配,随后采用“大语言模型作为评判者”(LLM-as-a-Judge)机制迭代验证规则。通过结合知识驱动的丰富化、基于模板的规则落地以及多阶段解决方案,AUTOSIGMA能够生成准确、上下文感知且相关的规则。对多个真实APT报告和多个安全博客的评估表明,AUTOSIGMA在规则有效性、规则相关性、MITRE ATT&CK技术覆盖范围以及对输入质量的鲁棒性方面,优于替代解决方案和大语言模型。AUTOSIGMA的演示:this https URL

英文摘要

Mechanisms for dynamically converting cyber threat intelligence (CTI) into actionable detection capabilities are necessary due to the rapid evolution of Advanced Persistent Threats (APTs). Sigma rules are an essential part of contemporary threat detection workflows because they offer a platform-independent framework for expressing detection logic that can be converted into particular queries across SIEM systems. Conventional techniques for manually crafting Sigma rules are prone to mistakes, and necessitate extensive knowledge, which restricts their scalability. Although there are open-source and industry-maintained Sigma rule repositories, they often fail to keep pace with emerging threats and require frequent customization to fit diverse operational environments. This emphasizes the necessity of dynamic rule generation that is adapted to evolving attack techniques as well as particular use cases. In this work, we design AUTOSIGMA, an automated solution for transforming unstructured CTI reports into relevant Sigma rules. Rather than relying solely on language models, AUTOSIGMA leverages a structured knowledge base to enrich partial inputs, matches the enriched content against a repository of existing Sigma rules, and then employs an LLM-as-a-Judge mechanism to iteratively validate the rules. By combining knowledge-driven enrichment, template-based rule grounding, and a multi-stage solution, AUTOSIGMA enables accurate, context-aware, and relevant rule generation. Evaluations across multiple real-world APT reports and multiple security blogs demonstrate that AUTOSIGMA outperforms alternative solutions and LLM models in rule validity, rule relevancy, MITRE ATT&CK technique coverage, and robustness to input quality. AUTOSIGMA's Demo: https://youtu.be/iSr6IurQ6BM

CommentsSubmitted for publication and currently under review

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑