Large Language Models powered Malicious Traffic Detection: Architecture, Opportunities and Case Study

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Xinggong, Meng, Haotian, Li, Qingyang, Tan, Yunpeng, Zhang, Lei
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913906327289856
author Zhang, Xinggong
Meng, Haotian
Li, Qingyang
Tan, Yunpeng
Zhang, Lei
author_facet Zhang, Xinggong
Meng, Haotian
Li, Qingyang
Tan, Yunpeng
Zhang, Lei
contents Malicious traffic detection is a pivotal technology for network security to identify abnormal network traffic and detect network attacks. Large Language Models (LLMs) are trained on a vast corpus of text, have amassed remarkable capabilities of context-understanding and commonsense knowledge. This has opened up a new door for network attacks detection. Researchers have already initiated discussions regarding the application of LLMs on specific cyber-security tasks. Unfortunately, there remains a lack of comprehensive analysis on harnessing LLMs for traffic detection, as well as the opportunities and challenges. In this paper, we focus on unleashing the full potential of Large Language Models (LLMs) in malicious traffic detection. We present a holistic view of the architecture of LLM-powered malicious traffic detection, including the procedures of Pre-training, Fine-tuning, and Detection. Especially, by exploring the knowledge and capabilities of LLM, we identify three distinct roles LLM can act in traffic classification: Classifier, Encoder, and Predictor. For each of them, the modeling paradigm, opportunities and challenges are elaborated. Finally, we present our design on LLM-powered DDoS detection as a case study. The proposed framework attains accurate detection on carpet bombing DDoS by exploiting LLMs' capabilities in contextual mining. The evaluation shows its efficacy, exhibiting a nearly 35% improvement compared to existing systems.
format Preprint
id arxiv_https___arxiv_org_abs_2503_18487
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Large Language Models powered Malicious Traffic Detection: Architecture, Opportunities and Case Study
Zhang, Xinggong
Meng, Haotian
Li, Qingyang
Tan, Yunpeng
Zhang, Lei
Networking and Internet Architecture
Artificial Intelligence
Cryptography and Security
Malicious traffic detection is a pivotal technology for network security to identify abnormal network traffic and detect network attacks. Large Language Models (LLMs) are trained on a vast corpus of text, have amassed remarkable capabilities of context-understanding and commonsense knowledge. This has opened up a new door for network attacks detection. Researchers have already initiated discussions regarding the application of LLMs on specific cyber-security tasks. Unfortunately, there remains a lack of comprehensive analysis on harnessing LLMs for traffic detection, as well as the opportunities and challenges. In this paper, we focus on unleashing the full potential of Large Language Models (LLMs) in malicious traffic detection. We present a holistic view of the architecture of LLM-powered malicious traffic detection, including the procedures of Pre-training, Fine-tuning, and Detection. Especially, by exploring the knowledge and capabilities of LLM, we identify three distinct roles LLM can act in traffic classification: Classifier, Encoder, and Predictor. For each of them, the modeling paradigm, opportunities and challenges are elaborated. Finally, we present our design on LLM-powered DDoS detection as a case study. The proposed framework attains accurate detection on carpet bombing DDoS by exploiting LLMs' capabilities in contextual mining. The evaluation shows its efficacy, exhibiting a nearly 35% improvement compared to existing systems.
title Large Language Models powered Malicious Traffic Detection: Architecture, Opportunities and Case Study
topic Networking and Internet Architecture
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2503.18487