FALCON: Autonomous Cyber Threat Intelligence Mining with LLMs for IDS Rule Generation

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Mitra, Shaswata, Bazarov, Azim, Duclos, Martin, Mittal, Sudip, Piplai, Aritran, Rahman, Md Rayhanur, Zieglar, Edward, Rahimi, Shahram
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866911121560043520
author Mitra, Shaswata
Bazarov, Azim
Duclos, Martin
Mittal, Sudip
Piplai, Aritran
Rahman, Md Rayhanur
Zieglar, Edward
Rahimi, Shahram
author_facet Mitra, Shaswata
Bazarov, Azim
Duclos, Martin
Mittal, Sudip
Piplai, Aritran
Rahman, Md Rayhanur
Zieglar, Edward
Rahimi, Shahram
contents Signature-based Intrusion Detection Systems (IDS) detect malicious activities by matching network or host activity against predefined rules. These rules are derived from extensive Cyber Threat Intelligence (CTI), which includes attack signatures and behavioral patterns obtained through automated tools and manual threat analysis, such as sandboxing. The CTI is then transformed into actionable rules for the IDS engine, enabling real-time detection and prevention. However, the constant evolution of cyber threats necessitates frequent rule updates, which delay deployment time and weaken overall security readiness. Recent advancements in agentic systems powered by Large Language Models (LLMs) offer the potential for autonomous IDS rule generation with internal evaluation. We introduce FALCON, an autonomous agentic framework that generates deployable IDS rules from CTI data in real-time and evaluates them using built-in multi-phased validators. To demonstrate versatility, we target both network (Snort) and host-based (YARA) mediums and construct a comprehensive dataset of IDS rules with their corresponding CTIs. Our evaluations indicate FALCON excels in automatic rule generation, with an average of 95% accuracy validated by qualitative evaluation with 84% inter-rater agreement among multiple cybersecurity analysts across all metrics. These results underscore the feasibility and effectiveness of LLM-driven data mining for real-time cyber threat mitigation.
format Preprint
id arxiv_https___arxiv_org_abs_2508_18684
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle FALCON: Autonomous Cyber Threat Intelligence Mining with LLMs for IDS Rule Generation
Mitra, Shaswata
Bazarov, Azim
Duclos, Martin
Mittal, Sudip
Piplai, Aritran
Rahman, Md Rayhanur
Zieglar, Edward
Rahimi, Shahram
Cryptography and Security
Artificial Intelligence
Computation and Language
Machine Learning
Systems and Control
Signature-based Intrusion Detection Systems (IDS) detect malicious activities by matching network or host activity against predefined rules. These rules are derived from extensive Cyber Threat Intelligence (CTI), which includes attack signatures and behavioral patterns obtained through automated tools and manual threat analysis, such as sandboxing. The CTI is then transformed into actionable rules for the IDS engine, enabling real-time detection and prevention. However, the constant evolution of cyber threats necessitates frequent rule updates, which delay deployment time and weaken overall security readiness. Recent advancements in agentic systems powered by Large Language Models (LLMs) offer the potential for autonomous IDS rule generation with internal evaluation. We introduce FALCON, an autonomous agentic framework that generates deployable IDS rules from CTI data in real-time and evaluates them using built-in multi-phased validators. To demonstrate versatility, we target both network (Snort) and host-based (YARA) mediums and construct a comprehensive dataset of IDS rules with their corresponding CTIs. Our evaluations indicate FALCON excels in automatic rule generation, with an average of 95% accuracy validated by qualitative evaluation with 84% inter-rater agreement among multiple cybersecurity analysts across all metrics. These results underscore the feasibility and effectiveness of LLM-driven data mining for real-time cyber threat mitigation.
title FALCON: Autonomous Cyber Threat Intelligence Mining with LLMs for IDS Rule Generation
topic Cryptography and Security
Artificial Intelligence
Computation and Language
Machine Learning
Systems and Control
url https://arxiv.org/abs/2508.18684