Context-Aware SIEM Rule Generation with LLMs: When Site Profiles Are Not Enough

Resumo


Security Information and Event Management (SIEM) platforms ship rulesets that are agnostic to the monitored organization, so a failed login receives the same severity in every environment. We investigate whether an LLM, conditioned only on a short organization profile and a catalog of native Wazuh rule identifiers, can write local rules that bring automated severity classification closer to human analyst judgment. On 1,000 stratified SSH authentication events from two production servers, the LLM-augmented configuration lowers accuracy by 4.4 percentage points and weighted F1 by 3.1 points relative to the native baseline. We trace the regression to a single failure mode, the over-escalation of unsuccessful login attempts from external sources, and discuss why aggregated F1 is a coarse proxy for rule quality.

Referências

Bertiger, A. et al. (2025). Evaluating LLM generated detection rules in cybersecurity. arXiv:2509.16749.

Du, M., Li, F., Zheng, G., and Srikumar, V. (2017). DeepLog: Anomaly detection and diagnosis from system logs through deep learning. In ACM CCS, pages 1285–1298.

Guo, H., Yuan, S., and Wu, X. (2021). LogBERT: Log anomaly detection via BERT. In IJCNN.

Han, X., Yuan, S., and Trabelsi, M. (2023). LogGPT: Log anomaly detection via GPT. In IEEE BigData, pages 1117–1122.

Hay, A., Cid, D., and Bray, R. (2008). OSSEC Host-Based Intrusion Detection Guide. Syngress.

Hindy, H. et al. (2020). A taxonomy of network threats and the effect of current datasets on intrusion detection systems. IEEE Access, 8:104650–104675.

Najafabadi, M. M., Khoshgoftaar, T. M., Calvert, C., and Kemp, C. (2015). Detection of SSH brute force attacks using aggregated Netflow data. In IEEE ICMLA, pages 283–288.

Schwartz, Y., Benshimol, L., Mimran, D., Elovici, Y., and Shabtai, A. (2024). LLMCloud-Hunter: Harnessing LLMs for automated extraction of detection rules from cloud-based CTI. arXiv:2407.05194.

Shukla, A., Gandhi, P. A., Elovici, Y., and Shabtai, A. (2025). RuleGenie: SIEM detection rule set optimization. arXiv:2505.06701.

Wudali, P. N. et al. (2025). Rule-ATT&CK mapper (RAM): Mapping SIEM rules to TTPs using LLMs. arXiv:2502.02337.
Publicado
01/09/2026
SCHAFHAUZER, Priscila; KAPELINSKI, Cristhian; POHLMANN, Marcio; KREUTZ, Diego. Context-Aware SIEM Rule Generation with LLMs: When Site Profiles Are Not Enough. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 1386-1392. DOI: https://doi.org/10.5753/sbseg.2026.29389.

Artigos mais lidos do(s) mesmo(s) autor(es)

1 2 3 4 5 6 7 8 9 10 > >>