Pith. sign in

REVIEW 2 cited by

RedChronos: A Large Language Model-Based Log Analysis System for Insider Threat Detection in Enterprises

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2503.02702 v2 pith:Z2JSO5IJ submitted 2025-03-04 cs.CR cs.LG

classification cs.CRcs.LG
keywords systemredchronoslogsdetectionenterprisessecurityanalysisinnovative
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Internal threat detection (IDT) aims to address security threats within organizations or enterprises by identifying potential or already occurring malicious threats within vast amounts of logs. Although organizations or enterprises have dedicated personnel responsible for reviewing these logs, it is impossible to manually examine all logs entirely.In response to the vast number of logs, we propose a system called RedChronos, which is a Large Language Model-Based Log Analysis System. This system incorporates innovative improvements over previous research by employing Query-Aware Weighted Voting and a Semantic Expansion-based Genetic Algorithm with LLM-driven Mutations. On the public datasets CERT 4.2 and 5.2, RedChronos outperforms or matches existing approaches in terms of accuracy, precision, and detection rate. Moreover, RedChronos reduces the need for manual intervention in security log reviews by approximately 90% in the Xiaohongshu Security Operation Center. Therefore, our RedChronos system demonstrates exceptional performance in handling IDT tasks, providing innovative solutions for these challenges. We believe that future research can continue to enhance the system's performance in IDT tasks while also reducing the response time to internal risk events.

Discussion (0). Sign in to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SimViews: An Interactive Multi-Agent System Simulating Visitor-to-Visitor Conversational Patterns to Present Diverse Perspectives of Artifacts in Virtual Museums

    cs.HC 2025-08 reject novelty 4.0 of 10

    The body text belongs to a different paper (Chimera), so the abstract's SimViews claims and its 20-participant study are unsupported in the submitted text.

  2. Evaluating Language Models For Threat Detection in IoT Security Logs

    cs.CR 2025-07 conditional novelty 4.0 of 10

    Fine-tuned open-source LLMs outperform classical ML classifiers on multiclass attack classification in the Edge-IIoTset dataset, while the mitigation-quality claims rest on a self-referential evaluation.

Pith tools