arrow
Return

Enhancing network security using knowledge graphs and large language models for explainable threat detection

delete2025-10-10
delete0
delete
OA
AI
L
Loris Belcastro
C
Carmine Carlucci
C
Cristian Cosentino
P
Píetro Lió
F
Fabrizio Marozzo
DOI:10.1016/j.future.2025.108160delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Ensuring robust cybersecurity in modern network environments is increasingly challenging due to the growing complexity and volume of network traffic data. Traditional detection systems often fail to identify stealthy and sophisticated attacks, such as Distributed Denial of Service (DDoS), ARP poisoning, and reconnaissance scans. Moreover, many existing methods lack transparency and produce reports that are difficult for analysts to interpret, slowing both threat comprehension and response. This paper addresses these challenges by introducing a novel methodology that integrates Knowledge Graphs, XAI techniques and Large Language Models (LLMs) to enhance network threat detection, classification, explainability, and automated reporting. The proposed approach employs Graph-BERT to encode complex communication patterns and semantic relationships into enriched knowledge graphs constructed from network logs. To ensure model transparency and interpretability, Local Interpretable Model-Agnostic Explanations (LIME) are incorporated, while structured prompts guide report generation using Generative AI. Experimental results obtained on benchmark datasets demonstrate that the methodology achieves a classification accuracy exceeding 84 %, outperforming existing detection techniques. Additionally, a comprehensive evaluation involving ablation analysis, LLM-based assessments, and expert reviews shows that incorporating structured knowledge and explainability significantly enhances the clarity, correctness, and informativeness of generated reports. These findings confirm the system’s effectiveness both as a detection mechanism and as a practical tool that helps analysts understand threats and craft informed responses.
Keywords:
Intrusion detection
Security log analysis
Knowledge graphs
Explainable AI
Large language models
Generative AI
Anomaly detection
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

F
Future Generation Computer Systems
IF:
0
Papers:
642
Citations:
0

Organization

U
University of Calabria
Scholars:
8.2K
Papers: 8.0K
Citations: 7.8K