University of Ontario Institute of Technology
Design and development of an LLM-driven end-to-end cybersecurity threat management framework
Abstract
dc:description.abstractSecurity Operations Centers (SOCs) rely on Security Information and Event Management (SIEM) systems to detect, investigate, and resolve cyber threats, but current SOC workflows remain highly manual, fragmented, and dependent on specialized analyst expertise. To address this challenge, this thesis presents an LLM-driven end-to-end threat management framework that connects threat classification, risk-based prioritization, automated evidence collection, and incident resolution support in a single pipeline. The framework combines machine learning, multiple LLMs, and ensemble decision-making to identify critical events and rank incidents by risk score. In the threat classification module, the proposed LLM ensemble achieves the best overall trade-off, with 82.8% accuracy. For investigation, the proposed Syntax Query Metadata (SQM) architecture uses syntax constraints, metadata retrieval, and documentation-grounded prompting to generate executable queries for IBM QRadar and Google SecOps. Compared with standalone LLM baselines, SQM improves query generation by more than two times in BLEU and by about 40% in ROUGE-L. The resolution module achieves 90.0% accuracy and an 8.70 recommendation quality score. Overall, the framework reduces analyst workload and supports faster, more consistent SOC decisions.
Degree
thesis:*- Name thesis:degree_name
- Master of Applied Science (MASc)
- Discipline thesis:degree_discipline
- Software Engineering
- Grantor
- University of Ontario Institute of Technology
- Year dc:date.issued
- 2026
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Saju, Md Hasan
- Advisor dc:contributor.advisor
-
- Azim, Akramul
Rights
- Language dc:language.iso
- en
Identifiers
dc:identifier.*- Handle dc:identifier.uri
- https://hdl.handle.net/10155/2126