Detail publikačního výsledku

Augmenting Security Logs with Artificial Intelligence: Are Deep Models the Missing Piece?

SAFONOV, Y.; FOLTÝN, O.

Originální název

Augmenting Security Logs with Artificial Intelligence: Are Deep Models the Missing Piece?

Anglický název

Augmenting Security Logs with Artificial Intelligence: Are Deep Models the Missing Piece?

Druh

Stať ve sborníku v databázi WoS či Scopus

Originální abstrakt

The analysis of security logs remains a major challenge for modern Security Information and Event Management (SIEM) systems due to insufficient standardization and diversity of log formats. While Artificial Intelligence (AI) offers great potential for automating monitoring, its use is limited by data sensitivity and a lack of annotated datasets. Augmentation can help generate realistic synthetic logs, providing broader opportunities for AI deployment. This article presents a framework for training language models to generate structured log variants, focusing on key metadata fields while maintaining syntactic consistency and semantic relevance. This framework increases data diversity, reduces the need for manual labeling, and facilitates the integration of AI into Security Operations Centers (SOCs), thereby enhancing operational efficiency. A heterogeneous corpus from 49 sources was cleaned, deduplicated, and transformed into semantically distinct entities. Two augmentation strategies were evaluated: Masked Language Modeling (MLM) and Next Word Prediction (NWP). Eight transformer-based models were finetuned and tested on simulated attack scenarios generated using the Atomic Red Team framework and compared with largescale models to assess accuracy and computational efficiency. The results demonstrate the potential of domain-specific language models for context-aware protocol augmentation, contributing to more efficient and automated security systems.

Anglický abstrakt

The analysis of security logs remains a major challenge for modern Security Information and Event Management (SIEM) systems due to insufficient standardization and diversity of log formats. While Artificial Intelligence (AI) offers great potential for automating monitoring, its use is limited by data sensitivity and a lack of annotated datasets. Augmentation can help generate realistic synthetic logs, providing broader opportunities for AI deployment. This article presents a framework for training language models to generate structured log variants, focusing on key metadata fields while maintaining syntactic consistency and semantic relevance. This framework increases data diversity, reduces the need for manual labeling, and facilitates the integration of AI into Security Operations Centers (SOCs), thereby enhancing operational efficiency. A heterogeneous corpus from 49 sources was cleaned, deduplicated, and transformed into semantically distinct entities. Two augmentation strategies were evaluated: Masked Language Modeling (MLM) and Next Word Prediction (NWP). Eight transformer-based models were finetuned and tested on simulated attack scenarios generated using the Atomic Red Team framework and compared with largescale models to assess accuracy and computational efficiency. The results demonstrate the potential of domain-specific language models for context-aware protocol augmentation, contributing to more efficient and automated security systems.

Klíčová slova

Security monitoring, Log augmentation, Transformer models, Log entity completion, Cybersecurity, NLP, NWP, SIEM, MLM, Security Operations Center

Klíčová slova v angličtině

Security monitoring, Log augmentation, Transformer models, Log entity completion, Cybersecurity, NLP, NWP, SIEM, MLM, Security Operations Center

Autoři

SAFONOV, Y.; FOLTÝN, O.

Rok RIV

2026

Vydáno

05.11.2025

Nakladatel

IEEE

Místo

Florence, Italy

ISBN

979-8-3315-7675-2

Kniha

2025 17th International Congress on Ultra Modern Telecommunications and Control Systems and Workshops (ICUMT)

Periodikum

International Congress on Ultra Modern Telecommunications and Workshops

Stát

Spojené státy americké

Strany od

40

Strany do

45

Strany počet

6

URL

BibTex

@inproceedings{BUT201114,
  author="Yehor {Safonov} and Ondřej {Foltýn}",
  title="Augmenting Security Logs with Artificial Intelligence: Are Deep Models the Missing Piece?",
  booktitle="2025 17th International Congress on Ultra Modern Telecommunications and Control Systems and Workshops (ICUMT)",
  year="2025",
  journal="International Congress on Ultra Modern Telecommunications and Workshops",
  pages="6",
  publisher="IEEE",
  address="Florence, Italy",
  doi="10.1109/ICUMT67815.2025.11268672",
  isbn="979-8-3315-7675-2",
  url="https://ieeexplore.ieee.org/document/11268672"
}