Skip to main navigation Skip to search Skip to main content

Integrating Large Language Models into Cybersecurity Incident Response: Enhancing Threat Detection and Analysis

  • Saifur Rahman Rahmani
  • University of Applied Sciences Technikum Wien

Research output: ThesisMaster's Thesis

Abstract

The inherent challenges in the current manual and repetitive practices of threat hunting during Incident Response necessitate more efficient and innovative approaches in cybersecurity operations. Traditional methods of manually crafting rules for identifying malicious patterns lack scalability and often suffer from low detection accuracy. This research integrates Large Language Models (LLMs) technology into Incident Response (IR) methodologies, aiming to instigate a paradigm shift in managing cybersecurity incidents. The envisaged benefits include heightened accuracy in threat detection, a reduction in false positives, and more efficient allocation of cybersecurity resources.
The primary objective is to alleviate the burden of repetitive and manual tasks faced by cybersecurity professionals by harnessing the capabilities of LLMs. This effort aims to facilitate expedited and informed decision-making processes during incident response scenarios, ultimately enhancing the effectiveness and efficiency of cybersecurity operations.
The methodology involves fine-tuning the Llama-3-8B-Instruct model on the
CIC-IDS2017 dataset and developing a Retrieval Augmented Generation (RAG) agent that provides a natural language interface for log analysis.
Results demonstrated that Llama-3-8B-Instruct (Llama-3) functions effectively as a conversational AI assistant, aiding in investigation, summarizing, and understanding threat intelligence. It automated repetitive tasks, thereby improving the speed and efficiency with which cybersecurity professionals respond to incidents. The model achieved an overall accuracy of 96.85%, demonstrating a high degree of predictive power in identifying various types of network attacks. These findings underscore the potential of the Llama-3 model in cybersecurity applications, particularly in detecting and classifying a wide range of network threats.
Original languageEnglish
QualificationMaster of Science
Awarding Institution
  • University of Applied Sciences Technikum Wien
Supervisors/Advisors
  • Schütz, Mina, Supervisor
Award date1 Jun 2024
Publication statusPublished - Jun 2024

Research Field

  • Multimodal Analytics

Keywords

  • Natural Language Processing

Fingerprint

Dive into the research topics of 'Integrating Large Language Models into Cybersecurity Incident Response: Enhancing Threat Detection and Analysis'. Together they form a unique fingerprint.

Cite this