SHIELD combines LOF anomaly detection, provenance graph clustering, and LLM chain-of-thought analysis to detect APT attacks and generate interpretable kill-chain summaries.
In: 32nd USENIX Security Symposium (USENIX Security 23)
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CR 1years
2025 1verdicts
CONDITIONAL 1representative citing papers
citing papers explorer
-
SHIELD: APT Detection and Intelligent Explanation Using LLM
SHIELD combines LOF anomaly detection, provenance graph clustering, and LLM chain-of-thought analysis to detect APT attacks and generate interpretable kill-chain summaries.