Abstract
The inherent challenges in the current manual and repetitive practices of threat hunting during Incident Response necessitate more efficient and innovative approaches in cybersecurity operations. Traditional methods of manually crafting rules for identifying malicious patterns lack scalability and often suffer from low detection accuracy. This research integrates Large Language Models (LLMs) technology into Incident Response (IR) methodologies, aiming to instigate a paradigm shift in managing cybersecurity incidents. The envisaged benefits include heightened accuracy in threat detection, a reduction in false positives, and more efficient allocation of cybersecurity resources.
The primary objective is to alleviate the burden of repetitive and manual tasks faced by cybersecurity professionals by harnessing the capabilities of LLMs. This effort aims to facilitate expedited and informed decision-making processes during incident response scenarios, ultimately enhancing the effectiveness and efficiency of cybersecurity operations.
The methodology involves fine-tuning the Llama-3-8B-Instruct model on the
CIC-IDS2017 dataset and developing a Retrieval Augmented Generation (RAG) agent that provides a natural language interface for log analysis.
Results demonstrated that Llama-3-8B-Instruct (Llama-3) functions effectively as a conversational AI assistant, aiding in investigation, summarizing, and understanding threat intelligence. It automated repetitive tasks, thereby improving the speed and efficiency with which cybersecurity professionals respond to incidents. The model achieved an overall accuracy of 96.85%, demonstrating a high degree of predictive power in identifying various types of network attacks. These findings underscore the potential of the Llama-3 model in cybersecurity applications, particularly in detecting and classifying a wide range of network threats.
The primary objective is to alleviate the burden of repetitive and manual tasks faced by cybersecurity professionals by harnessing the capabilities of LLMs. This effort aims to facilitate expedited and informed decision-making processes during incident response scenarios, ultimately enhancing the effectiveness and efficiency of cybersecurity operations.
The methodology involves fine-tuning the Llama-3-8B-Instruct model on the
CIC-IDS2017 dataset and developing a Retrieval Augmented Generation (RAG) agent that provides a natural language interface for log analysis.
Results demonstrated that Llama-3-8B-Instruct (Llama-3) functions effectively as a conversational AI assistant, aiding in investigation, summarizing, and understanding threat intelligence. It automated repetitive tasks, thereby improving the speed and efficiency with which cybersecurity professionals respond to incidents. The model achieved an overall accuracy of 96.85%, demonstrating a high degree of predictive power in identifying various types of network attacks. These findings underscore the potential of the Llama-3 model in cybersecurity applications, particularly in detecting and classifying a wide range of network threats.
| Originalsprache | Englisch |
|---|---|
| Qualifikation | Master of Science |
| Gradverleihende Hochschule |
|
| Betreuer/-in / Berater/-in |
|
| Datum der Bewilligung | 1 Juni 2024 |
| Publikationsstatus | Veröffentlicht - Juni 2024 |
Research Field
- Multimodal Analytics
Fingerprint
Untersuchen Sie die Forschungsthemen von „Integrating Large Language Models into Cybersecurity Incident Response: Enhancing Threat Detection and Analysis“. Zusammen bilden sie einen einzigartigen Fingerprint.Diese Publikation zitieren
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver