AI-Powered SOC Assistant

Authors

  • M. Sai Siri Shriya Department of Computer Science and Engineering, Vardhaman College of Engineering, Hyderabad, India
  • R. Aravind Rathod Department of Computer Science and Engineering, Vardhaman College of Engineering, Hyderabad, India
  • Krish Gupta Department of Computer Science and Engineering, Vardhaman College of Engineering, Hyderabad, India
  • V. Venkat Sai Krishna Department of Computer Science and Engineering, Vardhaman College of Engineering, Hyderabad, India
  • Rama Chandra Murthy Raju Department of Computer Science and Engineering, Vardhaman College of Engineering, Hyderabad, India

DOI:

https://doi.org/10.65890/dmp-lncse.ICICCS26.228

Keywords:

Security Operations Center (SOC), Cyber Threat Intelligence (CTI), Machine Learning, Anomaly Detection, Isolation Forest, Generative AI, Large Language Models (LLMs), Explainable AI (XAI), SIEM, Threat Hunting, Log Analysis, Risk-Based Alert Scoring.

Abstract

Cybersecurity threats are increasing rapidly as organizations rely more on digital infrastructure and online services. Security Operations Centres (SOCs) are responsible for monitoring and responding to these threats, but many still depend on manual investigation and static rule-based systems. These traditional approaches struggle to handle the large volume of alerts generated by modern networks. As a result, security analysts often face issues such as alert fatigue, delayed responses, and limited contextual information when analysing incidents, which can reduce the efficiency of security operations and increase the chances of missing critical threats. To address these challenges, this paper proposes an AI-Powered SOC Assistant that helps analysts detect and analyse potential security threats more effectively. The system combines machine learning techniques, natural language processing, and threat intelligence sources to analyse real-time security data collected from SIEM logs, OSINT sources, and external threat feeds. By correlating and analysing this information, the system can identify suspicious patterns and highlight possible attack indicators. The proposed solution also includes a risk-based alert-scoring mechanism to prioritise incidents by severity. An interactive dashboard and conversational interface allow analysts to explore alerts with natural-language queries and receive clear explanations and recommended response actions, improving investigation efficiency and overall SOC performance.

Downloads

Published

13-08-2026

Conference Proceedings Volume

Section

Articles

How to Cite

Shriya, M. S. S. ., Rathod, R. A., Gupta, K., V. Venkat Sai Krishna, & Rama Chandra Murthy Raju. (2026). AI-Powered SOC Assistant. DMPedia Lecture Notes in Computer Science & Engineering, ICICCS26, 470-479. https://doi.org/10.65890/dmp-lncse.ICICCS26.228