Key points are not available for this paper at this time.
The increasing complexity of network threats demands smarter and faster analytical tools. Existing models often struggle with zero-day attacks or high-volume traffic. Retrieval-augmented generation (RAG) offers a promising approach by combining retrieval from knowledge sources with generative reasoning. In this study, we evaluate and improve RAG-based architecture for network packet analysis. We propose a novel Hybrid Cache-Graph RAG framework that merges graph-based structural reasoning with strategic multi-level caching. Four architectures are compared: Traditional RAG, Graph RAG, Cache RAG, and the proposed hybrid model. Evaluation is conducted using intrusion detection evaluation dataset (CIC-IDS2017), the raw network packets (UNSW-NB15), and custom packet capture (PCAP) datasets across multiple metrics including accuracy, latency, and robustness under zero-day and high-load conditions. Results demonstrate that the Hybrid Cache-Graph RAG outperforms all baseline architectures, achieving an 18% improvement in retrieval accuracy (MAP) and a 54% reduction in latency. Ablation studies confirm the importance of adaptive component weighting in realizing these gains. This work underscores the value of integrating structural reasoning with memory optimization for building next-generation, adaptive cybersecurity solutions.
Mahmoud et al. (Fri,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: