arXiv AI By Sepehr Ghaffarzadegan, Boubakr Nour, Makan Pourzandi, Mourad Debbabi, Chadi Assi

From Threat Intelligence to Detection: Knowledge-driven Enrichment and Template-based Rule Grounding for Automated Sigma Rule Generation

Read the original on arXiv AI →

The paper introduces AUTOSIGMA, an automated system that converts unstructured cyber threat intelligence reports into Sigma detection rules. It enriches input data with a structured knowledge base, matches it against existing Sigma rule repositories, and uses a large language model as a judge to validate the generated rules. Experiments on real-world APT reports and security blogs show that AUTOSIGMA outperforms other methods in rule validity, relevancy, MITRE ATT&CK coverage, and robustness to input quality.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv AI
3d ago

CVE2AP: Automated Generation of PDDL-Encoded Attack Paths via Large Language Models

CVE2AP is an LLM-based system that automatically converts natural language CVE descriptions into PDDL-encoded attack paths. It uses structured prompting and an error‑feedback loop that refines outputs based on planner‑reported syntactic and solvability errors. Empirical tests across various LLMs show high quality results, with up to 86.9% syntax correctness, 78.6% solvability, and 93.1% semantic correctness, and GPT‑5.5 providing the best quality‑cost balance.

By Lin Cui, Vincenzo Scotti, Raffaela Mirandola