The rapid evolution of cyber threats necessitates the efficient detection of known and unknown encrypted malicious traffic data. Current detection approaches struggle with the cold start problem for unknown attacks, balancing detection accuracy with real-time performance and transfer capability. This paper presents MENTOR, a novel malicious network traffic detection framework that leverages optimized Large Language Models (LLMs) for enhanced detection ability. Through targeted fine-tuning strategies, MENTOR exploits LLMs’ semantic understanding and generalization abilities to process network traffic patterns. Experimental evaluation on multiple real-world datasets demonstrates MENTOR’s superior performance in identifying both known and emerging attack patterns compared to some SOTA approaches.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

MENTOR: Malicious Network Traffic Detection Through Optimized LLM-Based Recognition

  • Junxiang Jia,
  • Haoyang Meng,
  • Yizhong Hu,
  • Kexian Liu,
  • Jianfeng Guan

摘要

The rapid evolution of cyber threats necessitates the efficient detection of known and unknown encrypted malicious traffic data. Current detection approaches struggle with the cold start problem for unknown attacks, balancing detection accuracy with real-time performance and transfer capability. This paper presents MENTOR, a novel malicious network traffic detection framework that leverages optimized Large Language Models (LLMs) for enhanced detection ability. Through targeted fine-tuning strategies, MENTOR exploits LLMs’ semantic understanding and generalization abilities to process network traffic patterns. Experimental evaluation on multiple real-world datasets demonstrates MENTOR’s superior performance in identifying both known and emerging attack patterns compared to some SOTA approaches.