Welcome to the upgraded BRAC University Institutional Repository. We are currently organizing collections after a recent system upgrade. Homepage category counters may temporarily show lower numbers while syncing, but over 27,000 repository items remain safe and accessible. Please use the search bar to find theses, scholarly outputs, and institutional documents.

Designing an LLM-augmented framework for security evaluation and policy recommendation

bracu.degree.levelUndergraduate
bracu.type.groupStudent Works
datacite.rightsOpen Access
dc.contributor.advisorHossain, Muhammad Iqbal
dc.contributor.authorPasha, Md. Salman
dc.contributor.authorAhsan, KM Abrar
dc.contributor.authorNodi, Rumman
dc.contributor.authorMaliha, Shawana
dc.contributor.authorSiddiquee, Md. Eousuf
dc.contributor.departmentDepartment of Computer Science and Engineering
dc.date.accessioned2026-01-06T08:48:21Z
dc.date.available2026-01-06T08:48:21Z
dc.date.copyright2025
dc.date.issued2025-10
dc.descriptionCataloged from PDF version of thesis.
dc.descriptionIncludes bibliographical references (pages 52-54).
dc.descriptionThis thesis is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science, 2025.en_US
dc.description.abstractAs organizations continue to accumulate more data in the digital platforms, it becomes difficult to safeguard sensitive data. The authorization and authentication factors restrict the use of critical systems, but traditional IAM can’t scale with the new breed of cyber-threats like credential theft, phishing and AI attacks. The motive of this paper is in building security systems more resilient and intelligent to deal with any kind of malicious attacks and generating decisions with the application of Large Language Models (LLMs) augmented with advanced AI driven techniques. The project was initially focused on the specified access control factors of Identity and Access Management (IAM) and evaluating policies with providing security scores connected to web interfaces to analyze vulnerable factors beforehand. This was incorporated to a hybrid AI architecture consisting of a small BERT-tiny model optimized to detect security anomalies quickly and larger transformer based models LLMs (Mistral-7B and Gemma3-270M) that can be deployed to explain problems in fine detail and generate remediation strategies that can be executed. Experiments on larger actual datasets showed BERT-tiny achieved a remarkable accuracy of 90.12% for detection and 82.45% for malicious type differentiation. The focus applied on hyperparameter tuning, multi layer approach optimization, and class imbalance adjustments ensured robustness and generalization. Although certain limitations remain, especially in aspects of response latencies and the computational overhead, the present work is a step towards demonstrating the radical potential of an LLM approach in building systems that think faster, explain better, and adapt smarter to emerging digital threats.en_US
dc.description.degreeBachelor of Science in Computer Science
dc.description.statementofresponsibilityMd. Salman Pasha
dc.description.statementofresponsibilityKM Abrar Ahsan
dc.description.statementofresponsibilityRumman Nodi
dc.description.statementofresponsibilityShawana Maliha
dc.description.statementofresponsibilityMd. Eousuf Siddiquee
dc.format.extent63 pages
dc.identifier.otherID 24141081
dc.identifier.otherID 24141119
dc.identifier.otherID 23241082
dc.identifier.otherID 22101117
dc.identifier.otherID 24141082
dc.identifier.urihttp://hdl.handle.net/10361/27403
dc.language.isoenen_US
dc.publisherBRAC Universityen_US
dc.rightsBRAC University theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission.
dc.subjectLarge language modelsen_US
dc.subjectArtificial intelligenceen_US
dc.subjectBERT-tinyen_US
dc.subjectSecurity evaluationen_US
dc.subjectHyperparameter tuningen_US
dc.subjectMistral-7Ben_US
dc.subjectGemma3en_US
dc.subjectCybersecurityen_US
dc.subject.lcshCyberspace--Security measures--Evaluation.
dc.subject.lcshComputer networks--Security measures.
dc.subject.lcshComputer security.
dc.subject.lcshInformation networks--Security measures.
dc.subject.lcshArtificial intelligence--Security measures
dc.titleDesigning an LLM-augmented framework for security evaluation and policy recommendationen_US
dc.typeThesisen_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
24141081, 24141119, 22101117, 24141082, 23241082_CSE.pdf
Size:
1.2 MB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: