arXiv:2509.10858cs.CRcs.AI2025-09综述被引 28

LLM助力建立更高效智能的网络安全运营中心

Large Language Models for Security Operations Centers: A Comprehensive Survey

  • 用大模型自动化日志分析与事件分类
  • 提升威胁检测准确率,缩短响应时间
  • 适合安全研究人员与运维管理者参考

大语言模型(LLMs)在理解与生成类人文本方面展现出强大能力,为多个领域带来变革性潜力。网络安全运营中心(SOC)作为数字基础设施防护的前线,承担持续监控、事件检测与响应任务,却长期面临告警量大、资源有限、专家短缺、响应延迟及威胁情报利用困难等挑战。在此背景下,LLMs可通过自动化日志分析、简化告警优先级排序、提升检测准确性,并快速提供所需知识,助力解决上述问题。本文系统梳理生成式AI,尤其是LLMs在SOC工作流中的集成应用,从能力、挑战到未来方向提供结构化视角。我们相信该综述为研究者与SOC管理者提供了当前学术研究中LLM应用的全景图。据我们所知,这是首个对LLM在SOC中应用进行深入详尽探讨的综合性研究。

原文摘要 · Abstract (English)

Large Language Models (LLMs) have emerged as powerful tools capable of understanding and generating human-like text, offering transformative potential across diverse domains. The Security Operations Center (SOC), responsible for safeguarding digital infrastructure, represents one of these domains. SOCs serve as the frontline of defense in cybersecurity, tasked with continuous monitoring, detection, and response to incidents. However, SOCs face persistent challenges such as high alert volumes, limited resources, high demand for experts with advanced knowledge, delayed response times, and difficulties in leveraging threat intelligence effectively. In this context, LLMs can offer promising solutions by automating log analysis, streamlining triage, improving detection accuracy, and providing the required knowledge in less time. This survey systematically explores the integration of generative AI and more specifically LLMs into SOC workflow, providing a structured perspective on its capabilities, challenges, and future directions. We believe that this survey offers researchers and SOC managers a broad overview of the current state of LLM integration within academic study. To the best of our knowledge, this is the first comprehensive study to examine LLM applications in SOCs in details.

大模型安全运营AI安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。