Leveraging AI for Confident Classification and Prioritization of Intrusion Detection System Alerts

dc.contributor.advisorChehab, Ali
dc.contributor.authorMustafa, Ali
dc.contributor.commembersTawk, Youssef
dc.contributor.commembersSarieddeen, Hadi
dc.contributor.degreeME
dc.contributor.departmentDepartment of Electrical and Computer Engineering
dc.contributor.facultyMaroun Semaan Faculty of Engineering and Architecture
dc.contributor.institutionAmerican University of Beirut
dc.date2024
dc.date.accessioned2024-08-19T06:29:29Z
dc.date.available2024-08-19T06:29:29Z
dc.date.issued2024-08-18T21:00:00Z
dc.date.submitted2024-08-16T21:00:00Z
dc.description.abstractThe increasing complexity and volume of cybersecurity alerts significantly challenge threat detection efforts, particularly within Security Operations Centers (SOCs), where the high rate of false positives can obscure real and dangerous threats. This burden not only strains resources but also increases the risk of overlooking genuine security breaches. Leveraging advanced machine learning techniques, particularly Large Language Models (LLMs), this thesis introduces a novel methodology aimed at enhancing the precision of alert classifications from Windows endpoints’ security logs. This study extracted approximately 700 false and real threat cases from a real enterprise network. The proposed approach involves creating an Execution Graph for each alerting Windows process, which is then processed by a "Graph Contextualizer" block. This block transforms complex process interactions into structured, analyzable formats suitable for training and inference in large language models. The transformed data points are subsequently fed into several locally fine-tuned LLMs designed to classify the alerts accurately. Preliminary evaluation of this pipeline shows excellent metrics, achieving high levels of precision and recall, thereby substantiating the effectiveness of our approach. The methodology not only improves the operational efficiency of SOCs by reducing the investigative overhead of false threats and assisting in the detection of real threats but also contributes significantly to the broader field of cybersecurity, offering a scalable model for integrating machine learning into existing security infrastructures.
dc.identifier.urihttp://hdl.handle.net/10938/24547
dc.language.isoen
dc.subjectHost Intrusion Detection Systems (HIDS)
dc.subjectFalse Positives
dc.subjectLarge Language Models (LLM)
dc.subjectAlert Classification
dc.subjectAudit Logs
dc.subjectSecurity Operations Center (SOC)
dc.titleLeveraging AI for Confident Classification and Prioritization of Intrusion Detection System Alerts
dc.typeThesis
local.AUBID202370203

Files

Original bundle

Now showing 1 - 3 of 3
Loading...
Thumbnail Image
Name:
MustafaAli_2024.pdf
Size:
634.58 KB
Format:
Adobe Portable Document Format
Description:
Main Thesis
Loading...
Thumbnail Image
Name:
MustafaAli_ApprovalForm_2024.pdf
Size:
42.59 KB
Format:
Adobe Portable Document Format
Description:
Approval Form
Loading...
Thumbnail Image
Name:
MustafaAli_ReleaseForm_2024.pdf
Size:
625.46 KB
Format:
Adobe Portable Document Format
Description:
Release Form

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.65 KB
Format:
Item-specific license agreed upon to submission
Description: