{"id":{"repo_id":"uoit","oai_identifier":"oai:ontariotechu.scholaris.ca:10155/2126"},"canonical_url":"https://search.dev.ndltd.org/etd/uoit/oai:ontariotechu.scholaris.ca:10155/2126","repository":{"repo_id":"uoit","name":"Ontario Institute of Technology","base_url":"https://ontariotechu.scholaris.ca/server/oai/request"},"display":{"title":"Design and development of an LLM-driven end-to-end cybersecurity threat management framework","abstract":"Security Operations Centers (SOCs) rely on Security Information and Event Management (SIEM) systems to detect, investigate, and resolve cyber threats, but current SOC workflows remain highly manual, fragmented, and dependent on specialized analyst expertise. To address this challenge, this thesis presents an LLM-driven end-to-end threat management framework that connects threat classification, risk-based prioritization, automated evidence collection, and incident resolution support in a single pipeline. The framework combines machine learning, multiple LLMs, and ensemble decision-making to identify critical events and rank incidents by risk score. In the threat classification module, the proposed LLM ensemble achieves the best overall trade-off, with 82.8% accuracy. For investigation, the proposed Syntax Query Metadata (SQM) architecture uses syntax constraints, metadata retrieval, and documentation-grounded prompting to generate executable queries for IBM QRadar and Google SecOps. Compared with standalone LLM baselines, SQM improves query generation by more than two times in BLEU and by about 40% in ROUGE-L. The resolution module achieves 90.0% accuracy and an 8.70 recommendation quality score. Overall, the framework reduces analyst workload and supports faster, more consistent SOC decisions.","abstract_html":"Security Operations Centers (SOCs) rely on Security Information and Event Management (SIEM) systems to detect, investigate, and resolve cyber threats, but current SOC workflows remain highly manual, fragmented, and dependent on specialized analyst expertise. To address this challenge, this thesis presents an LLM-driven end-to-end threat management framework that connects threat classification, risk-based prioritization, automated evidence collection, and incident resolution support in a single pipeline. The framework combines machine learning, multiple LLMs, and ensemble decision-making to identify critical events and rank incidents by risk score. In the threat classification module, the proposed LLM ensemble achieves the best overall trade-off, with 82.8% accuracy. For investigation, the proposed Syntax Query Metadata (SQM) architecture uses syntax constraints, metadata retrieval, and documentation-grounded prompting to generate executable queries for IBM QRadar and Google SecOps. Compared with standalone LLM baselines, SQM improves query generation by more than two times in BLEU and by about 40% in ROUGE-L. The resolution module achieves 90.0% accuracy and an 8.70 recommendation quality score. Overall, the framework reduces analyst workload and supports faster, more consistent SOC decisions.","abstract_has_math":false,"creators":["Saju, Md Hasan"],"institution":"University of Ontario Institute of Technology","degree_name":"Master of Applied Science (MASc)","degree_level":null,"degree_discipline":"Software Engineering","degree_department":null,"school":null,"contributors":[],"advisors":["Azim, Akramul"],"committee_chairs":[],"committee_members":[],"year":2026,"date_issued":"2026-06-01","date_published":"2026-06-01","updated_at":"2026-08-21T16:49:53Z","subjects":[],"languages":["en"],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/10155/2126","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"source_record":{"url":"https://ontariotechu.scholaris.ca/server/oai/request?verb=GetRecord&metadataPrefix=dim&identifier=oai%3Aontariotechu.scholaris.ca%3A10155%2F2126","prefix":"dim"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Azim, Akramul"]},{"key":"dc:creator","label":"Author","values":["Saju, Md Hasan"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2026-07-28T20:01:51Z"]},{"key":"dc:date.issued","label":"Date","values":["2026-06-01"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Software Engineering"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Applied Science (MASc)"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Ontario Institute of Technology"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10155/2126"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Security Operations Centers (SOCs) rely on Security Information and Event Management (SIEM) systems to detect, investigate, and resolve cyber threats, but current SOC workflows remain highly manual, fragmented, and dependent on specialized analyst expertise. To address this challenge, this thesis presents an LLM-driven end-to-end threat management framework that connects threat classification, risk-based prioritization, automated evidence collection, and incident resolution support in a single pipeline. The framework combines machine learning, multiple LLMs, and ensemble decision-making to identify critical events and rank incidents by risk score. In the threat classification module, the proposed LLM ensemble achieves the best overall trade-off, with 82.8% accuracy. For investigation, the proposed Syntax Query Metadata (SQM) architecture uses syntax constraints, metadata retrieval, and documentation-grounded prompting to generate executable queries for IBM QRadar and Google SecOps. Compared with standalone LLM baselines, SQM improves query generation by more than two times in BLEU and by about 40% in ROUGE-L. The resolution module achieves 90.0% accuracy and an 8.70 recommendation quality score. Overall, the framework reduces analyst workload and supports faster, more consistent SOC decisions."]},{"key":"dc:title","label":"Title","values":["Design and development of an LLM-driven end-to-end cybersecurity threat management framework"]}]}],"canonical_facts":{"dc:contributor.advisor":["Azim, Akramul"],"dc:creator":["Saju, Md Hasan"],"dc:date.accessioned":["2026-07-28T20:01:51Z"],"dc:date.issued":["2026-06-01"],"dc:description.abstract":["Security Operations Centers (SOCs) rely on Security Information and Event Management (SIEM) systems to detect, investigate, and resolve cyber threats, but current SOC workflows remain highly manual, fragmented, and dependent on specialized analyst expertise. To address this challenge, this thesis presents an LLM-driven end-to-end threat management framework that connects threat classification, risk-based prioritization, automated evidence collection, and incident resolution support in a single pipeline. The framework combines machine learning, multiple LLMs, and ensemble decision-making to identify critical events and rank incidents by risk score. In the threat classification module, the proposed LLM ensemble achieves the best overall trade-off, with 82.8% accuracy. For investigation, the proposed Syntax Query Metadata (SQM) architecture uses syntax constraints, metadata retrieval, and documentation-grounded prompting to generate executable queries for IBM QRadar and Google SecOps. Compared with standalone LLM baselines, SQM improves query generation by more than two times in BLEU and by about 40% in ROUGE-L. The resolution module achieves 90.0% accuracy and an 8.70 recommendation quality score. Overall, the framework reduces analyst workload and supports faster, more consistent SOC decisions."],"dc:identifier.uri":["https://hdl.handle.net/10155/2126"],"dc:language.iso":["en"],"dc:title":["Design and development of an LLM-driven end-to-end cybersecurity threat management framework"],"dc:type":["Thesis"],"thesis:degree_discipline":["Software Engineering"],"thesis:degree_name":["Master of Applied Science (MASc)"],"thesis:institution_name":["University of Ontario Institute of Technology"]},"updated_at":"2026-08-21T16:49:53Z"}