{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:Z2JSO5IJFGW4MHBCLH6RSDZNDP","short_pith_number":"pith:Z2JSO5IJ","schema_version":"1.0","canonical_sha256":"ce9327750929adc61c2259fd190f2d1bdcbda8baf6da846b25f07a0745ce823f","source":{"kind":"arxiv","id":"2503.02702","version":2},"attestation_state":"computed","paper":{"title":"RedChronos: A Large Language Model-Based Log Analysis System for Insider Threat Detection in Enterprises","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Chenyu Li, Jiyan He, Xiu Zhang, Zhengjia Zhu","submitted_at":"2025-03-04T15:18:40Z","abstract_excerpt":"Internal threat detection (IDT) aims to address security threats within organizations or enterprises by identifying potential or already occurring malicious threats within vast amounts of logs. Although organizations or enterprises have dedicated personnel responsible for reviewing these logs, it is impossible to manually examine all logs entirely.In response to the vast number of logs, we propose a system called RedChronos, which is a Large Language Model-Based Log Analysis System. This system incorporates innovative improvements over previous research by employing Query-Aware Weighted Voting"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2503.02702","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-03-04T15:18:40Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"227d436723dd6b639a9b0f194aee761e867af019c20a6e0aa2e3632c11e9a1cc","abstract_canon_sha256":"b8249faff39d01ca91d3fd2cda3314ebd31bb86f5a419c3fab11fdf1b23f3565"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:30:31.900150Z","signature_b64":"5LngTW+C6peCjaOr9n7HBB7NIsFDo9UIduxW7Y5UfgF3/pGHUX+xxGbW5QHpdnGD3b+E3ERgPhIpLBzwdtnlDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ce9327750929adc61c2259fd190f2d1bdcbda8baf6da846b25f07a0745ce823f","last_reissued_at":"2026-07-05T10:30:31.899529Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:30:31.899529Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"RedChronos: A Large Language Model-Based Log Analysis System for Insider Threat Detection in Enterprises","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Chenyu Li, Jiyan He, Xiu Zhang, Zhengjia Zhu","submitted_at":"2025-03-04T15:18:40Z","abstract_excerpt":"Internal threat detection (IDT) aims to address security threats within organizations or enterprises by identifying potential or already occurring malicious threats within vast amounts of logs. Although organizations or enterprises have dedicated personnel responsible for reviewing these logs, it is impossible to manually examine all logs entirely.In response to the vast number of logs, we propose a system called RedChronos, which is a Large Language Model-Based Log Analysis System. This system incorporates innovative improvements over previous research by employing Query-Aware Weighted Voting"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2503.02702","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2503.02702/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2503.02702","created_at":"2026-07-05T10:30:31.899596+00:00"},{"alias_kind":"arxiv_version","alias_value":"2503.02702v2","created_at":"2026-07-05T10:30:31.899596+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2503.02702","created_at":"2026-07-05T10:30:31.899596+00:00"},{"alias_kind":"pith_short_12","alias_value":"Z2JSO5IJFGW4","created_at":"2026-07-05T10:30:31.899596+00:00"},{"alias_kind":"pith_short_16","alias_value":"Z2JSO5IJFGW4MHBC","created_at":"2026-07-05T10:30:31.899596+00:00"},{"alias_kind":"pith_short_8","alias_value":"Z2JSO5IJ","created_at":"2026-07-05T10:30:31.899596+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.10281","citing_title":"Benchmarking and Exploring the Capabilities of LLMs for Attack Investigations","ref_index":34,"is_internal_anchor":false},{"citing_arxiv_id":"2605.22027","citing_title":"Parser-Free Querying of Security Logs","ref_index":27,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/Z2JSO5IJFGW4MHBCLH6RSDZNDP","json":"https://pith.science/pith/Z2JSO5IJFGW4MHBCLH6RSDZNDP.json","graph_json":"https://pith.science/api/pith-number/Z2JSO5IJFGW4MHBCLH6RSDZNDP/graph.json","events_json":"https://pith.science/api/pith-number/Z2JSO5IJFGW4MHBCLH6RSDZNDP/events.json","paper":"https://pith.science/paper/Z2JSO5IJ"},"agent_actions":{"view_html":"https://pith.science/pith/Z2JSO5IJFGW4MHBCLH6RSDZNDP","download_json":"https://pith.science/pith/Z2JSO5IJFGW4MHBCLH6RSDZNDP.json","view_paper":"https://pith.science/paper/Z2JSO5IJ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2503.02702&json=true","fetch_graph":"https://pith.science/api/pith-number/Z2JSO5IJFGW4MHBCLH6RSDZNDP/graph.json","fetch_events":"https://pith.science/api/pith-number/Z2JSO5IJFGW4MHBCLH6RSDZNDP/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/Z2JSO5IJFGW4MHBCLH6RSDZNDP/action/timestamp_anchor","attest_storage":"https://pith.science/pith/Z2JSO5IJFGW4MHBCLH6RSDZNDP/action/storage_attestation","attest_author":"https://pith.science/pith/Z2JSO5IJFGW4MHBCLH6RSDZNDP/action/author_attestation","sign_citation":"https://pith.science/pith/Z2JSO5IJFGW4MHBCLH6RSDZNDP/action/citation_signature","submit_replication":"https://pith.science/pith/Z2JSO5IJFGW4MHBCLH6RSDZNDP/action/replication_record"}},"created_at":"2026-07-05T10:30:31.899596+00:00","updated_at":"2026-07-05T10:30:31.899596+00:00"}