RedChronos: A Large Language Model-Based Log Analysis System for Insider Threat Detection in Enterprises

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Li, Chenyu, Zhu, Zhengjia, He, Jiyan, Zhang, Xiu
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866915195866054656
author Li, Chenyu
Zhu, Zhengjia
He, Jiyan
Zhang, Xiu
author_facet Li, Chenyu
Zhu, Zhengjia
He, Jiyan
Zhang, Xiu
contents Internal threat detection (IDT) aims to address security threats within organizations or enterprises by identifying potential or already occurring malicious threats within vast amounts of logs. Although organizations or enterprises have dedicated personnel responsible for reviewing these logs, it is impossible to manually examine all logs entirely.In response to the vast number of logs, we propose a system called RedChronos, which is a Large Language Model-Based Log Analysis System. This system incorporates innovative improvements over previous research by employing Query-Aware Weighted Voting and a Semantic Expansion-based Genetic Algorithm with LLM-driven Mutations. On the public datasets CERT 4.2 and 5.2, RedChronos outperforms or matches existing approaches in terms of accuracy, precision, and detection rate. Moreover, RedChronos reduces the need for manual intervention in security log reviews by approximately 90% in the Xiaohongshu Security Operation Center. Therefore, our RedChronos system demonstrates exceptional performance in handling IDT tasks, providing innovative solutions for these challenges. We believe that future research can continue to enhance the system's performance in IDT tasks while also reducing the response time to internal risk events.
format Preprint
id arxiv_https___arxiv_org_abs_2503_02702
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle RedChronos: A Large Language Model-Based Log Analysis System for Insider Threat Detection in Enterprises
Li, Chenyu
Zhu, Zhengjia
He, Jiyan
Zhang, Xiu
Cryptography and Security
Machine Learning
Internal threat detection (IDT) aims to address security threats within organizations or enterprises by identifying potential or already occurring malicious threats within vast amounts of logs. Although organizations or enterprises have dedicated personnel responsible for reviewing these logs, it is impossible to manually examine all logs entirely.In response to the vast number of logs, we propose a system called RedChronos, which is a Large Language Model-Based Log Analysis System. This system incorporates innovative improvements over previous research by employing Query-Aware Weighted Voting and a Semantic Expansion-based Genetic Algorithm with LLM-driven Mutations. On the public datasets CERT 4.2 and 5.2, RedChronos outperforms or matches existing approaches in terms of accuracy, precision, and detection rate. Moreover, RedChronos reduces the need for manual intervention in security log reviews by approximately 90% in the Xiaohongshu Security Operation Center. Therefore, our RedChronos system demonstrates exceptional performance in handling IDT tasks, providing innovative solutions for these challenges. We believe that future research can continue to enhance the system's performance in IDT tasks while also reducing the response time to internal risk events.
title RedChronos: A Large Language Model-Based Log Analysis System for Insider Threat Detection in Enterprises
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2503.02702