RulePilot: An LLM-Powered Agent for Security Rule Generation
Hongtai Wang, Ming Xu, Yanpei Guo, Weili Han, Hoon Wei Lim, Jin Song Dong
Abstract
The real-time demand for system security leads to the detection rules becoming an integral part of the intrusion detection life-cycle. Rule-based detection often identifies malicious logs based on the predefined grammar logic, requiring experts with deep domain knowledge for rule generation. Therefore, automation of rule generation can result in significant time savings and ease the burden of rule-related tasks on security engineers. In this paper, we propose RulePilot, which mimics human expertise via LLM-based agent for addressing rule-related challenges like rule creation or conversion. Using RulePilot, the security analysts do not need to write down the rules following the grammar, instead, they can just provide the annotations such as the natural-language-based descriptions of a rule, our RulePilot can automatically generate the detection rules without more intervention. RulePilot is equipped with the intermediate representation (IR), which abstracts the complexity of config rules into structured, standardized formats, allowing LLMs to focus on generation rules in a more manageable and consistent way. We present a comprehensive evaluation of RulePilot in terms of textual similarity and execution success abilities, showcasing RulePilot can generate high-fidelity rules, outperforming the baseline models by up to 107.4% in textual similarity to ground truths and achieving better detection accuracy in real-world execution tests. We perform a case study from our industry collaborators in Singapore, showcasing that RulePilot significantly help junior analysts/general users in the rule creation process.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4fdb17d7-f61b-41e1-b706-086e82ee5c16Cited by top-tier papers2
- Generalizing Test Cases for Comprehensive Test Scenario CoverageBinhang Qi, Yun Lin, Xinyi Weng, Chenyan Liu et al.FSE 2026 · 1 citation
- ARuleCon: Agentic Security Rule ConversionMing Xu, Hongtai Wang, Yanpei Guo, Zhengmin Yu et al.WWW 2026
Builds on13
- Retrieval-Augmented Generation for Knowledge-Intensive NLP TasksPatrick Lewis, Ethan Perez, Aleksandra Piktus, Fabio Petroni et al.NeurIPS 2020 · 19,162 citations
- CodeT5: Identifier-aware Unified Pre-trained Encoder-Decoder Models for Code Understanding and GenerationYue Wang, Weishi Wang, Shafiq R. Joty, Steven C. H. HoiEMNLP 2021 · 1,224 citations
- Teaching Large Language Models to Self-DebugXinyun Chen, Maxwell Lin, Nathanael Schärli, Denny ZhouICLR 2024 · 1,085 citations
- Least-to-Most Prompting Enables Complex Reasoning in Large Language ModelsDenny Zhou, Nathanael Schärli, Le Hou, Jason Wei et al.ICLR 2023 · 318 citations
- Less is More: Quantifying the Security Benefits of Debloating Web ApplicationsBabak Amin Azad, Pierre Laperdrix, Nick NikiforakisUSENIX Security 2019 · 100 citations
Related papers
- AIR: Improving Agent Safety through Incident ResponseZibo Xiao, Jun Sun, Junjie ChenICML 2026 · 5 citations
- PatchPilot: A Cost-Efficient Software Engineering Agent with Early Attempts on Formal VerificationHongwei Li, Yuheng Tang, Shiqi Wang, Wenbo GuoICML 2025
- ExCyTIn-Bench: Evaluating LLM agents on Cyber Threat InvestigationYiran Wu, Mauricio Velazco, Andrew Zhao, Manuel Luján et al.ICML 2026 · 14 citations
- From Texts to Rules: Generating Sigma Rules with Large Language Models from Cyber Threat ReportsYongxin Cai, Jing Qiu, Qingming Li, Du Cheng et al.USENIX Security 2026
- TracePilot: Self-Verifiable Framework for Decentralized Applications Fault Localization across TransactionsXuanyu Zhu, Zhiying Wu, Tao Wang, Ying Yan et al.ISSTA 2026
