Přístupnostní navigace
E-application
Search Search Close
Master's Thesis
Author of thesis: Ing. Martin Šibor
Acad. year: 2025/2026
Supervisor: Ing. Yehor Safonov
Reviewer: prof. Ing. Kamil Říha, Ph.D.
This diploma thesis focuses on the design and implementation of a multi-agent system based on large language models, intended for assisted investigation of cyber incidents in unstructured data within a Security Operations Center environment. The addressed problem is based on the practice of analysts who are exposed to large volumes of heterogeneous logs and security events, whose manual processing is time-consuming, error-prone and delays the investigation of more severe incidents. The aim of the thesis is to design and implement a system capable of receiving an unstructured security event, converting it into a unified structure, identifying relevant indicators of compromise and enriching them with technical, reputational and internal context. The thesis first defines requirements arising from the Security Operations Center environment. This is followed by a comparison of suitable automation platforms, language models and security services, which serves as a basis for the design of the resulting architecture. The main contribution of the thesis is the proposal of an approach for dividing the processing of a security event between a coordinating agent and specialized agents, unifying the outputs of heterogeneous sources into a single structured representation and enriching them with context from a knowledge base and the history of previously processed events. Emphasis is placed on local deployment of language models, traceability of outputs and preserving the analyst’s decision-making role. Based on the proposed architecture, a functional system is implemented that provides normalization of input events, coordination of specialized agents, enrichment of indicators of compromise and presentation of the result to the analyst in a clear form. The functionality of the solution is verified on a set of test security events. The results show that the proposed system can automatically prepare supporting material for the initial assessment of an incident, make use of both external and internal context and support the analyst in follow-up queries over the knowledge base and the history of processed events.
Assisted investigation, indicators of compromise, knowledge base, large language models, local deployment, multi-agent system, n8n, Ollama, reputation services, Security Operations Center, vector store
Date of defence
09.06.2026
Result of the defence
Defended (thesis was successfully defended)
Grading
A
Process of defence
Student prezentoval výsledky své práce a komise byla seznámena s posudky. Student obhájil diplomovou práci a odpověděl na otázky členů komise a oponenta. Otázky: 1. Jaké hlavní limity vidíte při nasazení navrženého multiagentního systému v reálném produkčním prostředí SOC? 2. Jakým způsobem by bylo možné zvýšit důvěryhodnost a ověřitelnost odpovědí generovaných jednotlivými agenty? 3. Koľko lokálnych modelov ste použil? 4. Na akom hardware ste to spustil? 5. Bolo by možné zmeniť model? 6. Aký je rozdiel medzi dense modelmi a MOE modelmi? 7. Riešil ste problémy s halucináciami?
Language of thesis
Czech
Faculty
Fakulta elektrotechniky a komunikačních technologií
Department
Department of Telecommunications
Study programme
Information Security (MPC-IBE)
Composition of Committee
Ing. Eva Holasová, Ph.D. (člen) Ing. Petr Machník, Ph.D. (člen) doc. Ing. Petr Šiška, Ph.D. (místopředseda) JUDr. Pavel Loutocký, BA (Hons), Ph.D. (člen) prof. Ing. Radim Burget, Ph.D. (předseda) Ing. Petr Blažek, Ph.D. (člen) Ing. Ondřej Pospíšil, Ph.D. (člen) Ing. Jorge Truffin (člen)
Supervisor’s reportIng. Yehor Safonov
Grade proposed by supervisor: A
Reviewer’s reportprof. Ing. Kamil Říha, Ph.D.
Grade proposed by reviewer: A
Responsibility: Mgr. et Mgr. Hana Odstrčilová