Prasasthy Balasubramanian

dblp:367/0283 · DBLP profile ↗
← Back
2ranked-venue papers in the field
2as first author
2since 2021 · last 2024
0009-0002-4098-0333ORCID · corroborated

Domains — venue-derived; a paper can count in several

Big Data, Cloud & Distributed Data Systems · 2 (2 first)
YearPublicationVenuePosition
2024 Hex2Sign: Automatic IDS Signature Generation from Hexadecimal Data using LLMs
abstract
Despite the growing utilization of large language models (LLMs) in cyber defense operations, their integration within intrusion detection systems (IDS) remains substantially underexplored. This paper proposes a novel approach to generating human-readable IDS signatures by fine-tuning LLMs on hexadecimal data. In our experimental framework, we deploy honeypots to capture malicious network traffic in real-world conditions, generating packet capture (PCAP) files accompanied by text-based alerts and Suricata signatures. The collected hexadecimal data, derived from actual attack vectors, serves as the training corpus for multiple generative and classification models, which are fine-tuned for optimal performance in generating human-readable IDS alerts. According to the results, generative model GPT-3-Davinci-002 excelled across metrics with BERTscore over 96%, while RoBERTa base achieved high accuracy of 96% among classifiers. These findings enhance our understanding that foundational models can improve hexadecimal data processing for cybersecurity. Our conclusions emphasize the potential of advanced generative-AI models in automating dynamic Suricata rule generation, thus enhancing IDS efficiency and accuracy. Moreover, this paper proposes an AI-powered IDS system for securing network environments that can significantly mitigate the risks associated with diverse and widespread devices. By integrating LLMs into security frameworks, this system offers a robust defense mechanism that dynamically adapts to emerging threats, thus enhancing IDS efficiency and accuracy in handling big data challenges.
Prasasthy Balasubramanian, Tarek Ali, Mohammad Salmani, Danial Khosh Kholgh, Panos Kostakos 0001
IEEE Big Data1
2023 Transformer-based LLMs in Cybersecurity: An in-depth Study on Log Anomaly Detection and Conversational Defense Mechanisms
abstract
With the advancement of conversational AI and Large Language Models (LLMs), interactive chatbots are emerging as pivotal assets for connecting with users across various sectors, enabling various capabilities and functions. However, their potential in the cybersecurity domain remains largely untapped. This article introduces a novel method to enhance chatbot performance by incorporating anomaly detection features. Our chatbot uses advanced GPT-3 models and rule-based logic to identify and extract unusual patterns and deviations within logs, making it more proficient in detecting anomalies. We present the architecture and methodology behind our anomaly detection system, showcasing its effectiveness in real-world scenarios. Combining machine learning and domain expertise, our chatbot sets a new standard in interactive, anomaly-aware conversational agents. Our anomaly detection classifier was able to achieve more than 99% of accuracy by illustrating its robust performance in accurately identifying and flagging outliers or unusual patterns in log file data. We also compared the performance of GPT-3 models with other LLMs: BERT, DistilBERT, and ALBERT. Our findings concluded that GPT-3 models consistently outperform all the other LLM models and exhibit significantly higher performance.
Prasasthy Balasubramanian, Justin Seby, Panos Kostakos 0001
IEEE Big Data1