在网络安全中利用语言模型的力量:一个全面的回顾

Ramanpreet Kaur, Tomaž Klobučar, Dušan Gabrijelčič
{"title":"在网络安全中利用语言模型的力量:一个全面的回顾","authors":"Ramanpreet Kaur,&nbsp;Tomaž Klobučar,&nbsp;Dušan Gabrijelčič","doi":"10.1016/j.jjimei.2024.100315","DOIUrl":null,"url":null,"abstract":"<div><div>Language models are transforming cybersecurity by addressing critical challenges such as the growing skills gap, the need for expertise augmentation, and knowledge retention. These models offer scalable, adaptable, and round-the-clock defenses against evolving cyber threats. By generating human-like text, processing data efficiently, and providing actionable responses, language models bridge the gap between automated systems and human expertise for different cybersecurity applications. However, the application and adaptation of language models for cyber security is still in its infancy. This review explores the use of general models, such as BERT, and larger models in cybersecurity research. It provides a structured framework for developing customized language models tailored to applications including content analysis, software and systems analysis, threat intelligence and monitoring, and cyber vetting. The study critically examines challenges, such as data confidentiality, infrastructure requirements, integration complexity and the evolving threat landscape. Moreover, it underscores the need for transparency, responsible use, and bias mitigation to ensure reliable and secure deployment of these models. In addition, this work critically examines the socio-technical dimensions of language model integration, focusing on their impact on organizational workflows, decision making and human-machine collaboration. By considering both technical and socio-technical considerations, this review provides a roadmap for future research and development. It highlights the potential of language models to improve organizational resilience, ensure secure implementation, and support informed decision-making in cybersecurity practice.</div></div>","PeriodicalId":100699,"journal":{"name":"International Journal of Information Management Data Insights","volume":"5 1","pages":"Article 100315"},"PeriodicalIF":0.0000,"publicationDate":"2024-12-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Harnessing the power of language models in cybersecurity: A comprehensive review\",\"authors\":\"Ramanpreet Kaur,&nbsp;Tomaž Klobučar,&nbsp;Dušan Gabrijelčič\",\"doi\":\"10.1016/j.jjimei.2024.100315\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>Language models are transforming cybersecurity by addressing critical challenges such as the growing skills gap, the need for expertise augmentation, and knowledge retention. These models offer scalable, adaptable, and round-the-clock defenses against evolving cyber threats. By generating human-like text, processing data efficiently, and providing actionable responses, language models bridge the gap between automated systems and human expertise for different cybersecurity applications. However, the application and adaptation of language models for cyber security is still in its infancy. This review explores the use of general models, such as BERT, and larger models in cybersecurity research. It provides a structured framework for developing customized language models tailored to applications including content analysis, software and systems analysis, threat intelligence and monitoring, and cyber vetting. The study critically examines challenges, such as data confidentiality, infrastructure requirements, integration complexity and the evolving threat landscape. Moreover, it underscores the need for transparency, responsible use, and bias mitigation to ensure reliable and secure deployment of these models. In addition, this work critically examines the socio-technical dimensions of language model integration, focusing on their impact on organizational workflows, decision making and human-machine collaboration. By considering both technical and socio-technical considerations, this review provides a roadmap for future research and development. It highlights the potential of language models to improve organizational resilience, ensure secure implementation, and support informed decision-making in cybersecurity practice.</div></div>\",\"PeriodicalId\":100699,\"journal\":{\"name\":\"International Journal of Information Management Data Insights\",\"volume\":\"5 1\",\"pages\":\"Article 100315\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2024-12-19\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"International Journal of Information Management Data Insights\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2667096824001046\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Information Management Data Insights","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2667096824001046","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

语言模型通过解决日益扩大的技能差距、对专业知识增强的需求和知识保留等关键挑战,正在改变网络安全。这些模型提供可扩展的、可适应的、全天候的防御,以应对不断变化的网络威胁。通过生成类似人类的文本,有效地处理数据,并提供可操作的响应,语言模型弥合了自动化系统与不同网络安全应用程序的人类专业知识之间的差距。然而,语言模型在网络安全领域的应用和适应仍处于起步阶段。本文探讨了网络安全研究中一般模型(如BERT)和更大模型的使用。它提供了一个结构化框架,用于开发定制的语言模型,以适应包括内容分析、软件和系统分析、威胁情报和监控以及网络审查在内的应用。该研究对数据保密性、基础设施要求、集成复杂性和不断发展的威胁环境等挑战进行了批判性的审视。此外,它强调需要透明度、负责任的使用和减少偏见,以确保这些模型的可靠和安全部署。此外,这项工作批判性地考察了语言模型集成的社会技术维度,重点关注它们对组织工作流程、决策制定和人机协作的影响。通过考虑技术和社会技术因素,本综述为未来的研究和发展提供了路线图。它强调了语言模型在提高组织弹性、确保安全实施和支持网络安全实践中明智决策方面的潜力。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Harnessing the power of language models in cybersecurity: A comprehensive review
Language models are transforming cybersecurity by addressing critical challenges such as the growing skills gap, the need for expertise augmentation, and knowledge retention. These models offer scalable, adaptable, and round-the-clock defenses against evolving cyber threats. By generating human-like text, processing data efficiently, and providing actionable responses, language models bridge the gap between automated systems and human expertise for different cybersecurity applications. However, the application and adaptation of language models for cyber security is still in its infancy. This review explores the use of general models, such as BERT, and larger models in cybersecurity research. It provides a structured framework for developing customized language models tailored to applications including content analysis, software and systems analysis, threat intelligence and monitoring, and cyber vetting. The study critically examines challenges, such as data confidentiality, infrastructure requirements, integration complexity and the evolving threat landscape. Moreover, it underscores the need for transparency, responsible use, and bias mitigation to ensure reliable and secure deployment of these models. In addition, this work critically examines the socio-technical dimensions of language model integration, focusing on their impact on organizational workflows, decision making and human-machine collaboration. By considering both technical and socio-technical considerations, this review provides a roadmap for future research and development. It highlights the potential of language models to improve organizational resilience, ensure secure implementation, and support informed decision-making in cybersecurity practice.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
19.20
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信