Toward Agentic Intrusion Detection in the Internet of Things: Rule Generation and Live Validation for XRCE-DDS Attacks

Resumo


Signature-based IDSs rely on rules that must accurately capture attack behavior, yet public repositories provide limited coverage for emerging IoT and cyber-physical protocols such as XRCE-DDS. We present Rules Farmer, an open-source agentic tool that generates, deploys, and adversarially validates Snort 3 rules. A Defense Agent synthesizes signatures from natural-language intent, while an Attack Agent executes Docker-based attacks and evasive variants. Across four XRCE-DDS scenarios, 167 executions and 142 variants, 3 of 4 initial rules failed against the canonical attacks and required 15–23 revisions per scenario to converge. All campaigns converged within 50 executions, showing that live adversarial validation can expose semantic weaknesses that static validation misses.

Referências

Adewole, K. S., Jacobsson, A., and Davidsson, P. (2025). Intrusion detection framework for internet of things with rule induction for model explanation. Sensors, 25(6).

Cisco Snort Team (2024). Snort 3 rule writing guide. Accessed: May 15, 2026.

Cisco Talos Intelligence Group (2026). Snort 3 community ruleset. Accessed: May 21, 2026.

DeepSeek-AI (2026). DeepSeek-V4-Pro: Model card and api documentation. Model identifier deepseek-v4-pro. Accessed: May 15, 2026.

eProsima (2025). Micro XRCE-DDS documentation. Accessed: May 15, 2026.

Fu, Q. and Williams, D. (2026). Toward LLM-driven rule generation for enforcement systems: An exploratory study on WAF. AgenticOS Workshop, arXiv preprint. Accessed: May 15, 2026.

Husnain, M., Hayat, K., Cambiaso, E., Fayyaz, U. U., Mongelli, M., Akram, H., Ghazanfar Abbas, S., and Shah, G. A. (2022). Preventing mqtt vulnerabilities using iot-enabled intrusion detection system. Sensors, 22(2).

Li, J., Chai, Y., Du, L., Duan, C., Yan, H., and Gu, Z. (2025). Gridai: Generating and repairing intrusion detection rules via collaboration among multiple llm-based agents.

Lian, W., Zhang, C., Zhang, H., Jia, B., and Liu, B. (2025). Rulemaster+: Llm-based automated rule generation framework for intrusion detection systems. Chinese Journal of Electronics, 34(5):1402–1415.

Meng, C., Le, W., Li, X., Wang, Q., Ren, F., Jiang, Z., and Liu, B. (2026). From context to rules: Toward unified detection rule generation.

Moreno, M., Sáez-de Cámara, X., Urbieta, A., and Iturbe, M. (2025). Leveraging LLMs for automated IDS rule generation: A novel methodology for securing industrial environments. In Proceedings of X Jornadas Nacionales de Investigación en Ciberseguridad (JNIC 2025), pages 113–120, Zaragoza, Spain.

Quincozes, V. E., Quincozes, S. E., Kazienko, J. F., Gama, S., Cheikhrouhou, O., and Koubaa, A. (2024). A survey on IoT application layer protocols, security challenges, and the role of explainable AI in IoT (XAIoT). International Journal of Information Security, 23:1975–2002.

Singh, A., Chouhan, P. K., and Aujla, G. S. (2024). Secureflow: Knowledge and data-driven ensemble for intrusion detection and dynamic rule configuration in software-defined iot environment. Ad Hoc Networks, 156:103404.

Trend Micro Research (2022). A security analysis of the data distribution service (DDS) protocol. Technical report, Trend Micro.
Publicado
01/09/2026
CIOCCA, Matheus M.; FERREIRA, Emanuel C.; BARCELOS, Tuigg R.; QUINCOZES, Silvio E.; KREUTZ, Diego; SOUZA, Paulo Silas Severo de. Toward Agentic Intrusion Detection in the Internet of Things: Rule Generation and Live Validation for XRCE-DDS Attacks. In: SALÃO DE FERRAMENTAS - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 242-250. DOI: https://doi.org/10.5753/sbseg_estendido.2026.33720.

Artigos mais lidos do(s) mesmo(s) autor(es)

<< < 3 4 5 6 7 8 9 10 11 12 > >>