{"id":{"repo_id":"uoit","oai_identifier":"oai:ontariotechu.scholaris.ca:10155/1866"},"canonical_url":"https://search.dev.ndltd.org/etd/uoit/oai:ontariotechu.scholaris.ca:10155/1866","repository":{"repo_id":"uoit","name":"Ontario Institute of Technology","base_url":"https://ontariotechu.scholaris.ca/server/oai/request"},"display":{"title":"Smart monitoring of cybersecurity incidents using machine learning","abstract":"As cyber crime and Internet usage increase, cybersecurity solutions must evolve rapidly to keep pace. Despite significant advancements, these systems remain imperfect and are used daily by security analysts to monitor large networks, necessitating further improvements. Machine learning has gained traction in software development for added functionality, but its adoption in cybersecurity has been slow. This thesis introduces smart monitoring modules that employ machine learning to enhance cybersecurity tools and assist analysts in monitoring, investigating, and prioritizing threats. The anomaly detection module transforms log data into time series to detect abnormal activity, achieving an average F1 score of 87.24% across eight real-world datasets. Additionally, the threat assistance module utilizes historical threat tickets and state-of-the-art language models to classify and summarize threats, earning an F1 score of 85% across 38 cases and effectively summarizing relevant information in each instance.","abstract_html":"As cyber crime and Internet usage increase, cybersecurity solutions must evolve rapidly to keep pace. Despite significant advancements, these systems remain imperfect and are used daily by security analysts to monitor large networks, necessitating further improvements. Machine learning has gained traction in software development for added functionality, but its adoption in cybersecurity has been slow. This thesis introduces smart monitoring modules that employ machine learning to enhance cybersecurity tools and assist analysts in monitoring, investigating, and prioritizing threats. The anomaly detection module transforms log data into time series to detect abnormal activity, achieving an average F1 score of 87.24% across eight real-world datasets. Additionally, the threat assistance module utilizes historical threat tickets and state-of-the-art language models to classify and summarize threats, earning an F1 score of 85% across 38 cases and effectively summarizing relevant information in each instance.","abstract_has_math":false,"creators":["Page, Austin"],"institution":"University of Ontario Institute of Technology","degree_name":"Master of Applied Science (MASc)","degree_level":null,"degree_discipline":"Electrical and Computer Engineering","degree_department":null,"school":null,"contributors":[],"advisors":["Azim, Akramul"],"committee_chairs":[],"committee_members":[],"year":2024,"date_issued":"2024-10-01","date_published":"2024-10-01","updated_at":"2026-07-24T05:35:38Z","subjects":[],"languages":["en"],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/10155/1866","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Azim, Akramul"]},{"key":"dc:creator","label":"Author","values":["Page, Austin"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2024-12-03T16:43:05Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2024-12-03T16:43:05Z"]},{"key":"dc:date.issued","label":"Date","values":["2024-10-01"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical and Computer Engineering"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Applied Science (MASc)"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Ontario Institute of Technology"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10155/1866"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["As cyber crime and Internet usage increase, cybersecurity solutions must evolve rapidly to keep pace. Despite significant advancements, these systems remain imperfect and are used daily by security analysts to monitor large networks, necessitating further improvements. Machine learning has gained traction in software development for added functionality, but its adoption in cybersecurity has been slow. This thesis introduces smart monitoring modules that employ machine learning to enhance cybersecurity tools and assist analysts in monitoring, investigating, and prioritizing threats. The anomaly detection module transforms log data into time series to detect abnormal activity, achieving an average F1 score of 87.24% across eight real-world datasets. Additionally, the threat assistance module utilizes historical threat tickets and state-of-the-art language models to classify and summarize threats, earning an F1 score of 85% across 38 cases and effectively summarizing relevant information in each instance."]},{"key":"dc:title","label":"Title","values":["Smart monitoring of cybersecurity incidents using machine learning"]}]}],"canonical_facts":{"dc:contributor.advisor":["Azim, Akramul"],"dc:creator":["Page, Austin"],"dc:date.accessioned":["2024-12-03T16:43:05Z"],"dc:date.available":["2024-12-03T16:43:05Z"],"dc:date.issued":["2024-10-01"],"dc:description.abstract":["As cyber crime and Internet usage increase, cybersecurity solutions must evolve rapidly to keep pace. Despite significant advancements, these systems remain imperfect and are used daily by security analysts to monitor large networks, necessitating further improvements. Machine learning has gained traction in software development for added functionality, but its adoption in cybersecurity has been slow. This thesis introduces smart monitoring modules that employ machine learning to enhance cybersecurity tools and assist analysts in monitoring, investigating, and prioritizing threats. The anomaly detection module transforms log data into time series to detect abnormal activity, achieving an average F1 score of 87.24% across eight real-world datasets. Additionally, the threat assistance module utilizes historical threat tickets and state-of-the-art language models to classify and summarize threats, earning an F1 score of 85% across 38 cases and effectively summarizing relevant information in each instance."],"dc:identifier.uri":["https://hdl.handle.net/10155/1866"],"dc:language.iso":["en"],"dc:title":["Smart monitoring of cybersecurity incidents using machine learning"],"dc:type":["Thesis"],"thesis:degree_discipline":["Electrical and Computer Engineering"],"thesis:degree_name":["Master of Applied Science (MASc)"],"thesis:institution_name":["University of Ontario Institute of Technology"]},"updated_at":"2026-07-24T05:35:38Z"}