Back to search

Article

Using LLMs as AI Agents to Identify False Positive Alerts in Security Operation Center

2024-11-28

Abstract excerpt

<title>Abstract</title> <p>This paper addresses the challenges and solutions related to identifying false positive (FP) alerts in Security Information and Event Management (SIEM) systems, which often overwhelm security operators. To tackle this issue, we propose a novel approach that employs a Large Language Model (LLM), specifically Llama, as an AI agent through a contextual-based approach to identify FPs in sec...

Topics

Open a Topic to create a Post that cites this publication.

Identifiers and source

Literature Corpus work
e85c709e-1811-5a7d-8503-2ba5e1281c75
DOI
10.21203/rs.3.rs-5420741/v1
Open publication

Related research

Semantic proximity does not establish scientific evidence.

Click a neighbor to travelStep 1 · 12 closest
Interactive article relationship graphSelect a related publication card to move it into the centre and load its closest explainable connections. Solid lines are source-backed structured connections. Dashed lines are semantic discovery signals and are not scientific evidence.
Using LLMs as AI Agents to Identify False Positive Alerts in Security Operation CenterDOI 10.21203/rs.3.rs-5420741/v1
Select a neighboring publication to make it the new centre.