RuleAutoPilot: Synthesizing Deployable Suricata Rules from Network Traffic
cs.CR
Submitted: 2026-09-14
Updated: 2026-09-14
Code: https://github.com/iosifache/DikeDataset
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- TrafficLLM: Enhancing Large Language Models for Network Traffic Analysis with Generic Traffic Representation
- Beyond the Syntax: Do Security Experts Trust LLMs for NIDS Rule Engineering?
- GenTI: Benchmarking LLMs for Autonomous IDPS Rule Generation for Unseen Attacks
- ClarAVy: A Tool for Scalable and Accurate Malware Family Labeling
- GRIDAI: Generating and Repairing Intrusion Detection Rules via Collaboration among Multiple LLM-based Agents
- Studying Detection Rule Generation as a Unified Task
- NetGPT: Generative Pretrained Transformer for Network Traffic
- FALCON: Transforming Cyber Threat Intelligence into Deployable IDS Rules with Self-Reflection
- AI-Driven Cyber Threat Intelligence Automation
- Deep Learning-based Intrusion Detection Systems: A Survey
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs