A Prototype data agent for threat modelling in security operation centers

dc.contributor.authorOwino, M. O.
dc.date.accessioned2026-04-21T14:21:01Z
dc.date.issued2025
dc.descriptionFull - text thesis
dc.description.abstractThe rapidly evolving Cybersecurity threat landscape demands innovative threat modelling tools that can offer customized threat investigation in the complex and dynamic Security Operation Centers. This thesis outlines the development of a Data Agent designed to support Human Security Analysts in Security Operations Centers (SOCs). The system leverages advancements in generative artificial intelligence (GenAI) and in particular, Large Language Models (LLMs) and Retrieval Augmented Generation (RAG) to create an interactive Data Agent to augment human Security Analysts in investigating high risk threats. The main objective of this research is the design, development, and testing of a Large Language Model- Powered GenAI Agent that acts as a Data Agent, guiding human Security Analysts through the complexities of cybersecurity threat investigation. The intelligent Agent uses a conversational interface to provide explanations, answer questions and offer examples, thus engaging human Security Analysts in the Security Operation Centers. Methodologically, this research adopted a design science approach, involving the iterative development of the intelligent Agent system followed by rigorous testing in virtualized controlled environment. The system's effectiveness was evaluated based on its impact on threat investigation, accuracy levels, and user satisfaction. Keywords: artificial intelligence, cybersecurity, Data Agent, large language model, pre-trained transformer, false positives, retrieval augmented generation, threat investigation, security operations center
dc.identifier.citationOwino, M. O. (2025). A Prototype data agent for threat modelling in security operation centers [Strathmore University]. https://hdl.handle.net/11071/16437
dc.identifier.urihttps://hdl.handle.net/11071/16437
dc.language.isoen_US
dc.publisherStrathmore University
dc.titleA Prototype data agent for threat modelling in security operation centers
dc.typeThesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
A Prototype data agent for threat modelling in security operation centers.pdf
Size:
2.69 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: