Search papers, labs, and topics across Lattice.
This paper introduces (EC)2, a multi-agent framework designed to enhance explainability in cybersecurity by providing event-centric, detector-agnostic explanations for alerts. By focusing on contextual relationships and actionable insights, (EC)2 enables analysts to conduct structured, hypothesis-driven investigations that are grounded in verifiable evidence. Evaluation results indicate that this approach significantly improves the quality of post-detection analysis and boosts event classification accuracy in small- to medium-sized enterprise networks.
Event-centric explanations can transform cybersecurity investigations by providing actionable insights that improve alert handling and classification accuracy.
Security operations centers rely on anomaly detection systems to flag suspicious events. Feature-level explanations for anomaly detectors offer limited value for operational investigations. To effectively handle alerts, analysts need to know contextual relationships and need actionable understanding of the entities involved. This paper introduces an event-centric detector-agnostic approach for explaining cybersecurity alerts in small- to medium-sized enterprise networks. We present (EC)2, a multi-agent framework that performs structured, hypothesis-driven investigation to provide explanations grounded in verifiable evidence. Evaluation results show that the proposed framework improves post-detection analysis by generating operationally meaningful explanations, which also enhance event classification accuracy.