This study quantitatively demonstrated that AI-based intrusion incident analysis can be automated using a single graphics processing unit server under controlled evaluation conditions and provides a practical prototype for intelligent security monitoring in closed-network environments.
Abstract
Recent cyber incidents have become increasingly sophisticated through Living-off-the-Land (LotL) techniques that exploit legitimate behavior and multi-stage attacks. This requires advanced reasoning capabilities to discern the attack contexts within fragmented large-scale logs. However, closed network environments with physical network separation (air-gapped), such as national critical infrastructures, restrict the use of high-performance cloud large language models (LLMs), thereby limiting the adoption of cutting-edge artificial intelligence (AI)-based analysis technologies. To overcome these constraints, this study proposes a Local LLM-based intrusion analysis framework that operates independently within closed networks. The proposed framework combines (i) an Offline Knowledge Distillation technique that transfers the analytical reasoning process of external high-performance models to the Local LLM after a security review, and (ii) an AI agent orchestration structure that controls the analysis procedure step-by-step and suppresses hallucinations. Experiments and validation using a public dataset (Atomic Red Team) demonstrated that the proposed model achieved a consistently higher detection accuracy (88.4%) and MITRE Adversarial Tactics, Techniques, and Common Knowledge mapping performance (0.91 F1-Score) than existing general-purpose Local LLMs. Furthermore, the proposed model suppressed hallucination rates to 6.2% through an automated verification mechanism and significantly improved analysis efficiency by refining large-scale logs to focus on core events. This study quantitatively demonstrated that AI-based intrusion incident analysis can be automated using a single graphics processing unit server under controlled evaluation conditions. The proposed framework provides a practical prototype for intelligent security monitoring in closed-network environments. However, the operational performance must be validated in real-world deployments.
: Cybersecurity threats in Internet of Things (IoT) networks have escalated, enabled by rapid advancements in wireless communication and edge computing technologies. These advancements expose networks to a wide range of sophisticated and evolving threats and increasingly complex research challenges. Traditional Intrusion Detection and Prevention Systems (IDS/IPS) often fail to provide reliable performance regarding the flexibility and scalability required to handle evolving attack patterns. This study proposes an APENet approach to detect cyberattacks from a real-world cybersecurity dataset, and incorporated a contextual dependency mechanism. The approach captures both local transition dependencies and global relational interactions within structural sequences using bidirectional contextual aggregation and global attention-based interaction modeling. Furthermore, a protocol-aware feature normalization and preprocessing pipeline is developed, including hex-to-integer protocol field normalization, timestamp rebasing, and derivation of traffic dynamics indicators. Severe imbalance in the IoT cybersecurity dataset is addressed with synthetic minority oversampling and TomekLinks techniques to ensure balanced and representative training data. The proposed approach’s generalization and robustness are evaluated using stratified 5-fold cross-validation to ensure reliable performance across heterogeneous IoT scenarios. We did several experiments, and the proposed approach achieved remarkable performance for attack detection and underscored the model’s flexibility in adapting to various IoT environments. Furthermore, SHapley Additive exPlanations (SHAP) are incorporated to provide explainability, enabling the identification of key features influencing attack predictions and improving trust in model decisions. Overall, this study contributes a robust and adaptive security solution for strengthening IoT ecosystems against evolving cyber threats.
Muhammad Mujahid, Fatima Alshannaq, Shaha T. Al-Otaibi et al.· Computers, Materials & C...· 0 citations
This study presents a C*-algebraic framework for optimizing intrusion mitigation in Internet of Things (IoT)networks by integrating mathematical models for cyberattack propagation with optimization-based security strategies.Theoretical results demonstrate that the spectral radius of the attack operator ρ(A) governs the recovery of IoTnetworks under attack, where ρ(A) < 1 ensures system recovery, and ρ(A) ≥ 1 leads to persistent or growing attackimpact. The framework combines blockchain-based trust, AI-driven intrusion detection systems (IDS), and Zero-TrustArchitecture (ZTA) to provide a multi-layered, adaptive defence system. Unlike probabilistic models that simplifyattack dynamics, this approach rigorously models threats using bounded linear operators, thereby offering scalabilityand robustness. Optimization ensures computational efficiency, making the model suitable for resource-constrained IoTenvironments, with the operator norm and the spectral radius acting as key constraints. Validation on real-worlddatasets such as CIC-IoT2023, UNSW-NB15, and BoT-IoT revealed that the AI-IDS models achieved near-perfectperformance, while the unified model integrating blockchain, IDS, and ZTA showed an accuracy of 51.0
Mustapha Danjuma Suleiman· International Journal of Mat...· 0 citations
CyberLLM is presented, a multi-agent, LLM-orchestrated framework that autonomously detects vulnerabilities and executes remediations under a formal, runtime safety guard, and indicates that LLM agents can perform useful autonomous cyber-defense when wrapped in a deterministic, auditable safety envelope.
Nenad Petrovic, Oussama Jeddou, Feres Ben Fraj et al.· 0 citations
In light of the increased cyber-attacks and complex nature of IT infrastructure today, traditional monitoring systems for security have been identified to be slow and ineffective. Security Operation Centers (SOCs) still employ manual log analysis which causes delays in detecting threats and responding to them. In order to solve this problem, this paper presents the design of an Autonomous Incident Triage and Response Agent (AITRA). The proposed system is an easy and affordable solution which will be based on the idea behind SOAR technology. The proposed system seeks to automate the whole incident management lifecycle by carrying out tasks including log ingestion, event analysis, incident detection, and recommendation of responses. It receives data from sources such as system logs and authentication logs then analyzes them using rule-based analysis methods in order to detect suspicious activities such as failed login attempts, invalid access to the system by users, and escalation of privileges. A decision tree classifier machine learning algorithm is applied in order to categorize behaviors exhibited by the system and enhance detection capabilities. Detected incidents are recorded in a MariaDB database. Some of these responses include blocking IP addresses, suspending suspicious accounts, and informing the administrator. A user-friendly web-based interface that uses React and Flask technologies to help the user perform log upload, incident analysis, and receive appropriate responses is made possible by this software. Experimental evaluation results indicate that this new system makes more efficient use of time and effort than traditional methods and therefore provides better results. This is an implementation of a SOAR system in its miniature version which has the potential for further developments in future.
Dharshan Delwin D, Brindha D, Salaja Silas· 2026 7th International Confe...· 0 citations
The framework is presented as a bounded, server-assisted robustness-oriented training strategy for heterogeneous IoT/edge intrusion detection, and shows competitive primary performance and stronger robustness in several severe label-skew settings.
Xudong Yang, Zikui Lin, Qiuyan Li et al.· Electronics· 0 citations
The findings show that LLMs can approximate structured cybersecurity reasoning under controlled representations, but do not apply it robustly, which has important implications for the design and evaluation of AI-assisted security decision-support systems.
Pasquale Malacaria, Yunxiao Zhang· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.