

RulePilot turns SOC junior analysts into "security experts"
Toward Autonomous SIEM Rule Intelligence: Agentic AI for Scalable and Reliable Cyber Defense
Speaker: Ming Xu, Postdoc at NUS
Host: Boyang Xue, PhD at CUHK
NICE Talk 144🌟invites Ming Xu, Postdoc at NUS, to discuss agentic AI for scalable and reliable cyber defense. RulePilot employs an intermediate representation (IR) to simplify complex rule configurations into standardized formats, enhancing both accuracy and efficiency.
The paper demonstrates RulePilot’s superiority through comprehensive evaluations, showing up to a 107.4% improvement in textual similarity to established rules and effective detection in practical trials. It also facilitates seamless conversion between different Security Information and Event Management (SIEM) systems, addressing the compatibility issues resulting from varied rule languages.