简介
Even Eilertsen is a Doctoral Research Fellow in Digital Security at the Department of Informatics, University of Oslo, where he focuses on advancing cybersecurity through the integration of artificial intelligence. His research explores both AI for security—using advanced models to detect and mitigate threats—and security for AI, ensuring that intelligent systems themselves remain resilient against attacks. Recent work includes developing large language model–powered methods for intent-based categorization of phishing emails, aiming not only to detect malicious messages but also to extract actionable cyber threat intelligence from them. By combining expertise in cybersecurity, natural language processing, and threat analysis, Eilertsen contributes to building smarter, more adaptive de
代表成果
- Scientific articles and book chapters
- Eilertsen, Even; Mavroeidis, Vasileios & Grov, Gudmund (2025). Towards Agentic Investigation of Security Alerts. IEEE International Conference on Big Data (Big Data). ISSN 2639-1589. p. 7793–7802. doi: 10.1109/bigdata66926.2025.11402161. Full text in Research Archive Show summary Security analysts are overwhelmed by the volume of alerts and the low context provided by many detection systems. Early-stage investigations typically require manual correlation across multiple log sources, a task that is usually time-consuming. In this paper, we present an experimental, agentic workflow that leverages large language models (LLMs) augmented with predefined queries and constrained tool access (structured SQL over Suricata logs and grep-based text search) to automate the first stages of alert investigation. The proposed workflow integrates queries to provide an overview of the available data, and LLM components that selects which queries to use based on the overview results, extracts raw evidence from the query results, and delivers a final verdict of the alert. Our results demonstrate that the LLM-powered workflow can investigate log sources, plan an investigation, and produce a final verdict that has a significantly higher accuracy than a verdict produced by the same LLM without the proposed workflow. By recognizing the inherent limitations of directly applying LLMs to high-volume and unstructured data, we propose combining existing investigation practices of real-world analysts with a structured approach to leverage LLMs as virtual security analysts, thereby assisting and reducing the manual workload.
数据校验于 9/6/2026数据来源