DIGITAL LIBRARY
USING GENERATIVE AI TO SUPPORT STUDENT UNDERSTANDING OF SIEM RULE BEHAVIOUR
1 King's College London (UNITED KINGDOM)
2 University of Plymouth (UNITED KINGDOM)
About this paper:
Appears in: EDULEARN26 Proceedings
Publication year: 2026
Article: 1555
ISBN: 978-84-09-88444-5
ISSN: 2340-1117
doi: 10.21125/edulearn.2026.1555
Conference name: 18th International Conference on Education and New Learning Technologies
Dates: 29 June-1 July, 2026
Location: Palma, Spain
Abstract:
One area of expertise within the cybersecurity discipline of computing relates to the ability to understand and summarise security alerts, particularly those generated by security information and event management (SIEM) systems. Students must reason about and critically review large volumes of log data, rule-based protections, and diverse attack behaviours. Traditional instructional approaches tend to focus on rule syntax and alert thresholds rather than investigating relationships and causality across events. This paper outlines the design and evaluation of an AI-enhanced SIEM tool that aims to support students’ understanding of rule-based security analytics by leveraging GenAI-generated event correlations and explanations as learning resources. The tool translates SIEM rule behaviour into inspectable outputs, supporting the learning journey through comparison and critique of explanations. The proposed tool is evaluated using controlled log scenarios that cover both individual event alerts and multi-stage attacks. The analysis compares artefacts produced by rule-based and AI-assisted approaches in terms of coherence, error characteristics, bias sensitivity, and event correlation quality. The results indicate that AI-generated outputs produce more supportive learning artefacts, but also introduce unwanted effects such as prompt bias and excessive generalisation, which are pedagogically relevant from an AI critique perspective. We review the conceptual benefits of AI-augmented analysis as a scaffold for developing more inclusive security analytics teaching and discuss implications for the design of security laboratory activities. The paper presents a tool design, an evaluation framework, and a critical analysis that support the teaching of SIEM reasoning and attack correlation in computing education.
Keywords:
Educational tools, Interactive learning, AI and machine learning, Cybersecurity.