Abstract
The inherent challenges in the current manual and repetitive practices of threat hunting during Incident Response necessitate more efficient and innovative approaches in cybersecurity operations. Traditional methods of manually crafting rules for identifying malicious patterns lack scalability and often suffer from low detection accuracy. This research integrates Large Language Models (LLMs) technology into Incident Response (IR) methodologies, aiming to instigate a paradigm shift in managing cybersecurity incidents. The envisaged benefits include heightened accuracy in threat detection, a reduction in false positives, and more efficient allocation of cybersecurity resources.
The primary objective is to alleviate the burden of repetitive and manual tasks faced by cybersecurity professionals by harnessing the capabilities of LLMs. This effort aims to facilitate expedited and informed decision-making processes during incident response scenarios, ultimately enhancing the effectiveness and efficiency of cybersecurity operations.
The methodology involves fine-tuning the Llama-3-8B-Instruct model on the
CIC-IDS2017 dataset and developing a Retrieval Augmented Generation (RAG) agent that provides a natural language interface for log analysis.
Results demonstrated that Llama-3-8B-Instruct (Llama-3) functions effectively as a conversational AI assistant, aiding in investigation, summarizing, and understanding threat intelligence. It automated repetitive tasks, thereby improving the speed and efficiency with which cybersecurity professionals respond to incidents. The model achieved an overall accuracy of 96.85%, demonstrating a high degree of predictive power in identifying various types of network attacks. These findings underscore the potential of the Llama-3 model in cybersecurity applications, particularly in detecting and classifying a wide range of network threats.
The primary objective is to alleviate the burden of repetitive and manual tasks faced by cybersecurity professionals by harnessing the capabilities of LLMs. This effort aims to facilitate expedited and informed decision-making processes during incident response scenarios, ultimately enhancing the effectiveness and efficiency of cybersecurity operations.
The methodology involves fine-tuning the Llama-3-8B-Instruct model on the
CIC-IDS2017 dataset and developing a Retrieval Augmented Generation (RAG) agent that provides a natural language interface for log analysis.
Results demonstrated that Llama-3-8B-Instruct (Llama-3) functions effectively as a conversational AI assistant, aiding in investigation, summarizing, and understanding threat intelligence. It automated repetitive tasks, thereby improving the speed and efficiency with which cybersecurity professionals respond to incidents. The model achieved an overall accuracy of 96.85%, demonstrating a high degree of predictive power in identifying various types of network attacks. These findings underscore the potential of the Llama-3 model in cybersecurity applications, particularly in detecting and classifying a wide range of network threats.
| Original language | English |
|---|---|
| Qualification | Master of Science |
| Awarding Institution |
|
| Supervisors/Advisors |
|
| Award date | 1 Jun 2024 |
| Publication status | Published - Jun 2024 |
Research Field
- Multimodal Analytics
Keywords
- Natural Language Processing
Fingerprint
Dive into the research topics of 'Integrating Large Language Models into Cybersecurity Incident Response: Enhancing Threat Detection and Analysis'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver