AI-Powered SOC Assistant
DOI:
https://doi.org/10.65890/dmp-lncse.ICICCS26.228Keywords:
Security Operations Center (SOC), Cyber Threat Intelligence (CTI), Machine Learning, Anomaly Detection, Isolation Forest, Generative AI, Large Language Models (LLMs), Explainable AI (XAI), SIEM, Threat Hunting, Log Analysis, Risk-Based Alert Scoring.Abstract
Cybersecurity threats are increasing rapidly as organizations rely more on digital infrastructure and online services. Security Operations Centres (SOCs) are responsible for monitoring and responding to these threats, but many still depend on manual investigation and static rule-based systems. These traditional approaches struggle to handle the large volume of alerts generated by modern networks. As a result, security analysts often face issues such as alert fatigue, delayed responses, and limited contextual information when analysing incidents, which can reduce the efficiency of security operations and increase the chances of missing critical threats. To address these challenges, this paper proposes an AI-Powered SOC Assistant that helps analysts detect and analyse potential security threats more effectively. The system combines machine learning techniques, natural language processing, and threat intelligence sources to analyse real-time security data collected from SIEM logs, OSINT sources, and external threat feeds. By correlating and analysing this information, the system can identify suspicious patterns and highlight possible attack indicators. The proposed solution also includes a risk-based alert-scoring mechanism to prioritise incidents by severity. An interactive dashboard and conversational interface allow analysts to explore alerts with natural-language queries and receive clear explanations and recommended response actions, improving investigation efficiency and overall SOC performance.
Downloads
Published
Conference Proceedings Volume
Section
License
Copyright (c) 2026 DMPedia Lecture Notes in Computer Science & Engineering

This work is licensed under a Creative Commons Attribution 4.0 International License.