跳到正文
arXiv:cs.AI· Luoxi Tang, Yuqiao Meng, Ankita Patra, Weicheng Ma, Muchao Ye, Zhaohan Xi·· 6 小时前AI 评分27

POLAR:用 LLM 合成真实网络威胁证据以支持优先级排序与缓解

Polar: LLM-Powered Synthesis of Real-World Cyber Evidence for Prioritization and Mitigation

AI 导读

POLAR 是一个 LLM 驱动的框架,可将厂商公告、漏洞库和威胁情报中的碎片化证据合成为以威胁为中心的评估,用于优先级排序与缓解。它先分离重叠事件并将威胁锚定到可溯源证据,再结合严重性指标与按时间排序的利用信号估算近期被利用概率,并将威胁关联到权威修复知识、按紧迫性和操作约束组织处置动作。在公开资源收集的真实漏洞证据上,POLAR 在异构事件与零日场景中提升了威胁排序和缓解检索效果。

正文

View PDF HTML (experimental)

Abstract:Cyber threat analysis increasingly depends on evidence distributed across vendor advisories, vulnerability databases, and threat intelligence sources. Turning these fragmented observations into timely decisions requires models to connect technical severity with evolving exploitation evidence and available defensive actions. We present POLAR, an LLM-powered framework for synthesizing real-world cyber evidence into threat-centric assessments for prioritization and mitigation. POLAR first disentangles overlapping incidents and grounds each threat in source-linked evidence. For prioritization, it infers severity metrics from cyber evidence and combines the resulting assessment with temporally ordered exploitation signals to estimate near-term exploitation likelihood. For mitigation, it links the synthesized threat data to authoritative remediation knowledge and organizes applicable actions according to threat urgency and operational constraints. We evaluate POLAR on real-world vulnerability evidence collected from public resources and compare it with multiple baselines. Across heterogeneous incidents and zero-day settings, POLAR improves threat ranking and mitigation retrieval while producing evidence-linked intermediate assessments that support analyst inspection. The results establish evidence synthesis as a practical foundation for LLM-based cyber decision support across related security tasks.
Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI)
Cite as: arXiv:2610.07298 [cs.CR]
  (or arXiv:2610.07298v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2610.07298

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Luoxi Tang [view email]
[v1] Mon, 5 Oct 2026 19:36:49 UTC (1,141 KB)

来源:arXiv:cs.AI · arxiv.org