Publication Date

12-2025

Date of Final Oral Examination (Defense)

10-24-2025

Type of Culminating Activity

Dissertation

Degree Title

Doctor of Philosophy in Computing

Department

Computer Science

Supervisory Committee Chair

Edoardo Serra, Ph.D.

Supervisory Committee Co-Chair

Sam Ehrlich, Ph.D.

Supervisory Committee Member

Francesca Spezzano, Ph.D.

Supervisory Committee Member

Nasir Eisty, Ph.D.

Abstract

In an era when rapidly evolving adversarial tactics render traditional rule based defenses inadequate, this dissertation designs and develops a next generation cybersecurity framework that unifies agentic AI reasoning with graph grounded retrieval to automate cybersecurity operations through intelligence ingestion, detection, explanation, and response. This dissertation implements three novel contributions into the agentic framework.

The first contribution develops dual algorithms addressing phishing threats in the era of Large Language Models (LLMs). The attack algorithm transforms detectable malicious phishing emails using a novel agentic automatic output optimization technique while preserving semantic meaning and Indicators of Compromise (IOC). This approach successfully bypasses institutional security tools, natural language processing (NLP) systems, and LLM detection mechanisms, achieving attack success rates up to 98%. The corresponding defensive algorithm counters these advanced threats, identifying malicious emails with up to 97% improved accuracy. These results validated the technique's effectiveness and supported the filing of a provisional patent, which further informed the deployment within a Department of Energy (DOE) Laboratory through the POST system, demonstrating real world applicability against Advanced Persistent Threats (APTs).

The second contribution establishes the first automated framework for extracting Tactics, Techniques and Procedures (TTPs) and generating Sigma rules from Cyber Threat Intelligence (CTI) without requiring LLM fine-tuning. The approach designs a novel Reflective Beam Search (RBS) with Knowledge Graph Retrieval Augmented Generation (KG RAG) to iteratively refine outputs while maintaining alignment with source intelligence. A key innovation involves automatically constructing a densified cybersecurity knowledge graph that interconnects CTI with MITRE ATT&CK, CVEs, CAPEC, CWEs, and related security data. This enhancement improves contextual retrieval by establishing connections between critical cyber concepts. The framework achieves an 88% F1-score for TTP extraction from CTI and generates Sigma rules with a 76% True Positive Score (TPS), thus establishing the first quantitative benchmark on automated Sigma rule generation without model fine-tuning. These detections maintain robustness as surface indicators evolve, shifting defensive focus from ephemeral IOC to persistent adversarial tradecraft patterns.

The third contribution designs an agentic framework for analyzing raw log data to identify TTPs and generate real time explanations without model fine-tuning. Two algorithms are developed which form the framework's core. LLMLogSchemaGen employs agentic reasoning to identify TTPs from raw logs or Sigma rules and construct structured schema for systematic analysis, while LLMLogNarrator transforms these schema into comprehensive incident reports in natural language. Both algorithms operate through the KG RAG system to ensure analysis remains grounded in established CTI frameworks. Empirical evaluation demonstrates up to 93.9% accuracy in TTP identification, effective distillation of thousands of logs to essential indicators, and generation of explanation reports with 4 to 10 times greater analytical density than leading commercial solutions. Performance consistency across large datasets validates enterprise scalability, representing the first quantitative benchmark for automated LLM security log analysis and explanation without model fine-tuning.

These contributions create a self correcting, graph enhanced agentic cybersecurity framework that transitions from IOC to tradecraft centered detection and reasoning. This architecture demonstrates how the novel automatic output optimization techniques, combined with KG RAG, deliver production ready capabilities that enhance detection fidelity, reduce false positives, and operationalize CTI at the scale and speed required for modern security operations.

DOI

https://doi.org/10.18122/td.2449.boisestate

Available for download on Wednesday, December 01, 2027

Share

COinS