Skip to content
Open access

LLM-Driven Alert Correlation and Lifecycle Prediction With Threat Intelligence for Attack Forensics

2026 · IEEE Transactions on Machine Learning in Communications and Networking · Vol 4, pp. 1491-1512 · 0 citations · 41 references

Abstract

Security Operations Centers face overwhelming volumes of alerts from firewalls, intrusion detection systems, and other sources. These alerts often lack temporal and semantic coherence, hindering analysts from reconstructing full MITRE ATT&CK lifecycles or anticipating subsequent techniques. To address this, we propose a framework for alert correlation and lifecycle prediction, named LANCE (Lifecycle Analysis with Neural Correlation Engine). LANCE leverages large language models (LLMs) to consolidate heterogeneous alerts into structured, time-ordered sequences, while Cyber Threat Intelligence (CTI) provides semantic grounding. A Gemma 3-4B LLM serves as the backbone, with lightweight parameter adaptation enabling specialization for cybersecurity tasks without sacrificing real-time efficiency. The design combines three elements: structured prompts that transform raw alerts into coherent narratives, CTI-guided supervision that aligns telemetry with ATT&CK techniques, and efficient adaptation strategies that minimize computational overhead. Results show that without CTI, the highest achievable accuracy is only 27.82%, while integrating CTI improves performance to 64.76%. Using all available telemetry yields the highest prediction accuracy, whereas removing even one source, such as firewall logs, drops accuracy by nearly 30%. Together, these findings show that CTI integration, comprehensive telemetry, and efficient LLM reasoning enable accurate, real-time forensic analysis and proactive defense.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.