본문 바로가기
  • Home

A Two-Stage Framework for Cybersecurity Scenario Matching Using Embedding-Based Top-K Filtering and LLM Contextual Verification

  • Journal of The Korea Society of Computer and Information
  • Abbr : JKSCI
  • 2026, 31(7), pp.117~126
  • Publisher : The Korean Society Of Computer And Information
  • Research Area : Engineering > Computer Science
  • Received : May 20, 2026
  • Accepted : July 14, 2026
  • Published : July 31, 2026

Jihun Jang 1 Jungpyo Hong 2

1한국재료연구원
2국립창원대학교

Accredited

ABSTRACT

Traditional Security Information and Event Management and Security Orchestration, Automation, and Response systems are widely used to detect cyber threats. However, rule-based detection methods have difficulty identifying complex attacks that require contextual understanding. This study proposes a two-stage threat scenario matching system that combines vector embedding and Large Language Model analysis. First, the system retrieves the Top-K most similar threat scenarios using embedding-based similarity search. Then, the LLM compares the candidate scenarios with the input security alerts and selects the best match. Experimental results using simulated breach data demonstrated that the detection accuracy, which was 91.54% in the embedding stage, was significantly enhanced through the LLM’s contextual re-verification, successfully identifying all threat scenarios with zero misclassifications.

Citation status

* References for papers published after 2025 are currently being built.