REVIEW 1 cited by
Towards Automatic Hands-on-Keyboard Attack Detection Using LLMs in EDR Solutions
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
Endpoint Detection and Remediation (EDR) platforms are essential for identifying and responding to cyber threats. This study presents a novel approach using Large Language Models (LLMs) to detect Hands-on-Keyboard (HOK) cyberattacks. Our method involves converting endpoint activity data into narrative forms that LLMs can analyze to distinguish between normal operations and potential HOK attacks. We address the challenges of interpreting endpoint data by segmenting narratives into windows and employing a dual training strategy. The results demonstrate that LLM-based models have the potential to outperform traditional machine learning methods, offering a promising direction for enhancing EDR capabilities and apply LLMs in cybersecurity.
Forward citations
Cited by 1 Pith paper
-
Exploring the Role of Large Language Models in Cybersecurity: A Systematic Survey
A survey that organizes LLM-based cybersecurity defense by attack-phase, threat-intelligence, and deployment categories, and identifies post-intrusion defense as the main understudied area.
Discussion (0). Continue with ORCID to comment.