arrow
Return

L2DAPT – LLMs and Linux: decoding advanced persistent threats

delete2025-12-12
delete0
PRE
AI
S
Syed Sohaib Karim
M
Mehreen Afzal
W
Waseem Iqbal *
F
Farooq Zaman
I
Imran Rashid
DOI:10.1007/s11227-025-08129-2delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The increasing complexity and frequency of cyber-attacks, particularly advanced persistent threats (APTs), reveal the significant limitations of existing security mechanisms. As adversaries leverage artificial intelligence (AI) and substantial resources, their tactics have become more organized and potent, allowing them to consistently evade conventional detection. To address this critical security gap, we propose a novel machine learning (ML)-based framework for high-fidelity threat detection. This task is challenged by high-volume, high-velocity Linux system telemetry, which necessitates the real-time processing and massive parallelization inherent to high-performance computing (HPC) infrastructure. This solution utilizes a range of learning algorithms, including RF, feedforward neural networks (FNN), and convolutional neural networks (CNN), to accurately detect and predict sophisticated malicious activities, including zero-day exploits. A key innovation of our system is the integration of a large language model (LLM) as a post-detection analytical module. The LLM does not perform classification but is used exclusively to generate detailed, human-readable descriptions and contextual explanations for threats already identified with high confidence by the ML models, requires significant distributed computing resources to generate detailed and human-readable descriptions of the identified threats. This synergy empowers the defenders with the contextual understanding needed to develop effective countermeasures. We validated our approach on a novel, custom-generated dataset built from simulating advanced, multi-stage attacks. The results demonstrate the superior efficacy of the framework, achieving precision of 97% and 99% recall, thus providing a robust and insightful solution for modern cyber defense investigations.
Keywords:
Advanced persistent threat (APT)
Large language model (LLM)
Linux systems
Tactics techniques and procedures (TTPs)
MITRE
Artificial intelligence (AI)

Journal

T
The Journal of Supercomputing
IF:
0
Papers:
647
Citations:
0

Organization

I
information technology university (itu)
Scholars:
2
Papers: 2
Citations: 0
D
department of information security
Scholars:
8
Papers: 4
Citations: 0