Forensic analysis of web server logs demands both accurate detection and human-readable explanations that can satisfy legal requirements. We present CEF-Log, a context-enhanced few-shot chain-of-thought prompting strategy for Large Language Models that addresses this dual requirement. CEF-Log embeds expert investigative methodology through a structured five-step reasoning template, enabling the model to learn \textit{how} to analyze logs rather than \textit{what} patterns to memorize. Experimental evaluation demonstrates that CEF-Log achieves an F1-score of 0.99 on the CSIC 2010 dataset using only four examples while providing a $10\times$ improvement in sample efficiency compared to other prompting-based methods. We also introduce ForenWebLog, a new dataset that incorporates real-world attacks and multi-step attack sequences for comprehensive evaluation. Qualitative analysis confirms that CEF-Log generates traceable, accurate explanations suitable for forensic documentation, addressing the critical "black-box" limitation of traditional machine learning approaches.
翻译:Web服务器日志的取证分析既需要高精度检测,也需要满足法律要求的人类可读解释。我们提出了CEF-Log——一种面向大语言模型的上下文增强型少样本思维链推理策略,以应对这一双重需求。CEF-Log通过结构化的五步推理模板嵌入专家调查方法论,使模型学习"如何"分析日志而非记忆"什么"模式。实验评估表明,CEF-Log在CSIC 2010数据集上仅使用四个示例即可达到0.99的F1分数,相比其他基于提示的方法实现了10倍的样本效率提升。我们还引入了ForenWebLog——一个包含真实世界攻击场景与多步攻击序列的新数据集,用于全面评估。定性分析证实,CEF-Log生成的解释具有可追溯性与准确性,适用于取证文档编制,从而弥补了传统机器学习方法在"黑箱"问题上的关键缺陷。