CyberGuardian: An Interactive Assistant for Cybersecurity Specialists Using Large Language Models

Ciprian Paduraru, Catalina Patilea, Alin Stefanescu, Alin Stefanescu

2024

Abstract

Cybersecurity plays an important role in protecting people and critical infrastructure. Sectors such as energy, defense and healthcare are increasingly at risk from cyber threats. To address these challenges, dedicated Security Operations Centers (SOCs) continuously monitor threats and respond to critical issues. Our research focuses on the use of Large Language Models (LLMs) to optimize the tasks of SOCs and to support security professionals. In this work, we propose a framework, which we call CyberGuardian, whose main goal is to provide a chatbot application along with a set of tools to support SOC analysts in real-time cybersecurity tasks. We use state-of-the-art LLM techniques and start from a Llama 2 model, then fine-tune the base model using a new dataset containing mainly cybersecurity topics. The CyberGuardian framework has a plugin architecture that integrates processes such as Retrieval Augmented Generation (RAG), safeguard methods for interaction between human user and chatbot, integration with tools to manage tasks such as database interactions, code generation and execution, and plotting graphs just by specifying the task in a natural language. The work, along with the dataset we collected and reusable code to update or customize, is made available to the cybersecurity community as open source.

Download


Paper Citation


in Harvard Style

Paduraru C., Patilea C. and Stefanescu A. (2024). CyberGuardian: An Interactive Assistant for Cybersecurity Specialists Using Large Language Models. In Proceedings of the 19th International Conference on Software Technologies - Volume 1: ICSOFT; ISBN 978-989-758-706-1, SciTePress, pages 442-449. DOI: 10.5220/0012811700003753


in Bibtex Style

@conference{icsoft24,
author={Ciprian Paduraru and Catalina Patilea and Alin Stefanescu},
title={CyberGuardian: An Interactive Assistant for Cybersecurity Specialists Using Large Language Models},
booktitle={Proceedings of the 19th International Conference on Software Technologies - Volume 1: ICSOFT},
year={2024},
pages={442-449},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0012811700003753},
isbn={978-989-758-706-1},
}


in EndNote Style

TY - CONF

JO - Proceedings of the 19th International Conference on Software Technologies - Volume 1: ICSOFT
TI - CyberGuardian: An Interactive Assistant for Cybersecurity Specialists Using Large Language Models
SN - 978-989-758-706-1
AU - Paduraru C.
AU - Patilea C.
AU - Stefanescu A.
PY - 2024
SP - 442
EP - 449
DO - 10.5220/0012811700003753
PB - SciTePress