CYBER SAGE: AN LLM-ENHANCED EXPLAINABLE MACHINE LEARNING FRAMEWORK FOR INTELLIGENT CYBER THREAT DETECTION AND AUTOMATED INCIDENT RESPONSE

Authors

  • Waleed Khan Author
  • Muhammad Sarfraz Khan Author
  • Naseer Ahmad Author
  • Amirmohammad Delshadi Author

Keywords:

Cybersecurity, Explainable AI, Large Language Models, XAI, SHAP, Intrusion Detection System, Incident Response, RAG, Machine Learning, SOC Automation

Abstract

The increasing sophistication of cyberattacks has exposed significant limitations in traditional intrusion detection systems, including high false positive rates, limited interpretability, delayed incident response, and the inability to effectively detect emerging and previously unseen threats. Although machine learning-based intrusion detection systems have substantially improved attack detection accuracy by learning complex patterns from large-scale network traffic, most existing models operate as black boxes, making it difficult for cybersecurity analysts to interpret model decisions, validate predictions, and rapidly mitigate security incidents. To address these challenges, this paper proposes Cyber Sage, an integrated Explainable Artificial Intelligence (XAI) and Large Language Model (LLM)-enhanced cybersecurity framework for intelligent cyber threat detection and automated incident response. The proposed framework combines ensemble machine learning algorithms, including XG Boost, Random Forest, and Light GBM, with SHAP-based   to provide transparent and interpretable threat predictions. Network traffic is first collected, preprocessed, and classified using the ensemble model, after which SHAP identifies the most influential features contributing to each prediction. These feature-level explanations are subsequently supplied to a Large Language Model through a Retrieval-Augmented Generation (RAG) architecture integrated with Cyber Threat Intelligence (CTI) sources, enabling contextual threat reasoning, MITRE ATT&CK mapping, severity assessment, attack explanation, and evidence-based remediation recommendations. Furthermore, Cyber Sage incorporates a dynamic risk-scoring mechanism and an automated incident response engine capable of prioritizing security alerts, generating investigation reports, notifying Security Operations Center (SOC) analysts, and initiating predefined mitigation actions to reduce response time and analyst workload. Experimental evaluation conducted using the CICIDS2017 and CSE-CIC-IDS2018 benchmark datasets demonstrates that Cyber Sage achieves an overall detection accuracy of 99.4%, significantly reduces false positive rates, improves explain ability, and accelerates incident response compared with conventional machine learning-based intrusion detection systems. The integration of explainable machine learning, LLM reasoning, Retrieval-Augmented Generation, and automated response within a unified architecture enhances transparency, operational trust, and SOC efficiency, providing a scalable and effective solution for next-generation AI-driven cybersecurity systems.

Downloads

Published

31-12-2024

How to Cite

CYBER SAGE: AN LLM-ENHANCED EXPLAINABLE MACHINE LEARNING FRAMEWORK FOR INTELLIGENT CYBER THREAT DETECTION AND AUTOMATED INCIDENT RESPONSE. (2024). International Journal of Social Sciences Bulletin, 2(4), 2668-2679. https://ijssbulletin.com/index.php/IJSSB/article/view/2631