Betreuer/in: Al Sardy

Security Operations Center (SOC) analysts must often enrich raw intrusion detection alerts with vulnerability and threat intelligence before meaningful triage decisions can be made. This research investigates whether small, locally deployable language models (SLMs) combined with Retrieval-Augmented Generation (RAG) can support automated, privacy-preserving triage of Snort alerts. An end-to-end pipeline was developed that enriches alerts with Snort rule information and CVE data from the National Vulnerability Database (NVD).
Three SLMs were evaluated across three retrieval configurations: alert only, alert with rule context, and alert with rule and CVE context: using 25 ground-truth alerts covering 23 CVEs.
Results show that rule retrieval increases CVE identification accuracy to 100%, while adding CVE information substantially improves CVSS severity estimation. However, residual CVE hallucinations, weak MITRE ATT&CK mapping, and experiments with corrupted retrieval context demonstrate important reliability limitations. The findings indicate that RAG-enhanced local SLMs can effectively assist SOC analysts by reducing manual enrichment effort, but should be deployed as human-in-the-loop decision-support systems rather than autonomous triage mechanisms.
Raum 04.137, Martensstr. 3, Erlangen
oder
Zoom:
https://fau.zoom-x.de/j/68350702053?pwd=UkF3aXY0QUdjeSsyR0tyRWtLQ0hYUT09
Meeting-ID: 683 5070 2053
Kenncode: 647333