CEF-Log Web Log Detection

Arxiv pdf 2025-12-08T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Forensic analysis of web server logs demands both accurate detection and human-readable explanations that can satisfy legal requirements. We present CEF-Log, a contextenhanced few-shot chain-of-thought prompting strategy for Large Language Models that addresses this dual requirement. CEFLog embeds expert investigative methodology through a structured five-step reasoning template, enabling the model to learn how to analyze logs rather than what patterns to memorize. Experimental evaluation demonstrates that CEF-Log achieves an F1-score of 0.99 on the CSIC 2010 dataset using only four examples while providing a 10 improvement in sample efficiency compared to other prompting-based methods. We also introduce ForenWebLog, a new dataset that incorporates realworld attacks and multi-step attack sequences for comprehensive evaluation. Qualitative analysis confirms that CEF-Log generates traceable, accurate explanations suitable for forensic documentation, addressing the critical black-box limitation of traditional machine learning approaches.

Loading executive summary...

LINK COPIED TO CLIPBOARD