LLM-Based Analysis for Discovering Cybersecurity Patterns in Public Administration Cyber Events

Abstract
Public Administration cyber event records often contain incomplete, ambiguous, or undetermined information, which makes it difficult to understand incident behavior, affected government functions, and hidden cybersecurity risks through structured data alone. This paper proposes an LLM-assisted semantic analysis approach to interpret public-sector cyber event records by combining available structured attributes with narrative incident descriptions. The framework defines three interpretable metrics: Incident Security Semantics, Governance Function Criticality, and Cyber Intelligence Gap and Inference. These metrics capture the security meaning of each incident, the criticality of the affected public-sector function, and the intelligence value of incomplete records. The goal is to uncover security patterns that are not directly visible in the original records, including service disruption, sensitive data exposure, public safety impact, governance-related risk, and unresolved intelligence gaps. The proposed approach transforms fragmented event information into interpretable cybersecurity insights and supports context-aware analysis of public-sector incidents. The results demonstrate that the proposed LLM-assisted analysis can reveal recurring hidden patterns in cyber events and provide cyber threat intelligence for understanding risks to government services, citizen-facing systems, and sensitive public-sector operations.
© 2026 Puya Pakshad, Maurice Dawson, Enkel Hoxha, Abdul Hadi Khan, published by Nicolae Balcescu Land Forces Academy
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.