用大模型让AI和安全分析师协同工作,提升响应效率
Towards AI-Driven Human-Machine Co-Teaming for Adaptive and Agile Cyber Security Operation Centers
- 让AI通过学习人类分析师经验,掌握隐性知识
- 提升威胁情报、告警分类和事件响应能力
- 适合想提升安全运营效率的团队
安全运营中心(SOC)面临告警数量庞大、专业人才短缺及工具整合不足等挑战。人机协作为增强分析师能力、减轻认知负担提供了新路径。本文提出一种基于大语言模型(LLM)的AI驱动人机协同范式,使AI代理在威胁情报、告警分类和事件响应流程中持续优化。该范式通过学习人类分析师在实际操作中积累的隐性知识,实现性能迭代。我们邀请各安全运营中心参与合作,共同探索可复制的人机协同模式,以实现可量化的运营效率提升。
原文摘要 · Abstract (English)
Security Operations Centers (SOCs) face growing challenges in managing cybersecurity threats due to an overwhelming volume of alerts, a shortage of skilled analysts, and poorly integrated tools. Human-AI collaboration offers a promising path to augment the capabilities of SOC analysts while reducing their cognitive overload. To this end, we introduce an AI-driven human-machine co-teaming paradigm that leverages large language models (LLMs) to enhance threat intelligence, alert triage, and incident response workflows. We present a vision in which LLM-based AI agents learn from human analysts the tacit knowledge embedded in SOC operations, enabling the AI agents to improve their performance on SOC tasks through this co-teaming. We invite SOCs to collaborate with us to further develop this process and uncover replicable patterns where human-AI co-teaming yields measurable improvements in SOC productivity.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。