Idea
Model detecting insider and advanced persistent threats from security logs with interpretable risk indicators for improved zero-shot accuracy.
Research Paper
Core Innovation
This paper introduces a two-stage LLM framework that first generates structured, interpretable risk indicators from heterogeneous logs, then classifies these indicators across time to capture complex attack patterns. It leverages retrieval-augmented generation to personalize context and significantly improves zero-shot detection performance over prior LLM-based methods.
Why It Matters
Insider threats and APTs cause significant security breaches but are hard to detect due to complex, evolving patterns. This approach improves detection accuracy without requiring labeled data, enabling faster, scalable threat identification and reducing risk exposure for organizations.
Market Size (TAM)
$20B–$50B TAM for cybersecurity threat detection platforms; $5B–$10B SAM from enterprises and government agencies. Driven by rising cyberattack frequency and regulatory compliance demands.
Potential Customers & Pain Points
- Enterprises – Difficulty detecting insider threats early
- Cybersecurity firms – Need scalable accurate threat detection tools
- Government agencies – Require advanced APT detection without extensive training data
- Managed security service providers – Need interpretable alerts to prioritize responses
Business Model
Subscription-based SaaS platform offering threat detection APIs and dashboards with tiered pricing based on data volume and feature access.
Competitive Landscape
- Darktrace
- CrowdStrike
- Vectra AI
- Microsoft Defender
- IBM QRadar
Implementation Challenges
- Integration complexity with diverse security log sources
- Dependence on LLM performance and computational costs
- Adoption resistance due to trust in AI-generated risk indicators
Validation Strategy
- Pilot deployments with cybersecurity teams in enterprises
- Benchmarking against existing threat detection solutions on real-world datasets
- User studies to assess interpretability and operational impact of risk indicators
Research Paper Overview
LLMs for Zero-Shot Threat Detection via Structured Risk Indicators
Summary
A two-stage LLM framework detects insider threats and APTs from security logs by generating structured risk indicators and classifying them over time, outperforming prior models on benchmark datasets.