安全团队用大模型提效,但真刀实枪分析攻击仍靠人。
From Chasing Ghosts to Missed Attacks: Perspectives and Perceptions of SOC Practitioners on LLM Integration, Risks, and Readiness

- 通过25名分析师访谈,梳理出15种大模型在安全运维中的实际用法。
- 大模型能自动写报告,但分析攻击时深度不足、难懂业务背景。
- 适合想落地AI的安全团队,尤其关注人机协作与风险管控者。
安全运营中心(SOC)需在高压下快速识别和评估网络攻击,处理海量安全事件。尽管大语言模型(LLM)有望提升效率,但其在真实工作流中的适用性尚不明确。本研究对25位有大模型使用经验的SOC从业者进行半结构化访谈,并设计交互场景,识别出15个具体应用案例,涵盖六大功能类别。虽然从业者认可大模型在自动化低级任务(如生成报告)上的价值,但普遍认为其在高阶任务(如事件分析)中仍不可靠,主要受限于技术深度、上下文理解能力及组织特异性知识缺失。这些瓶颈更多源于机构准备度和人为因素,而非模型本身。尽管存在担忧,受访者仍表现出强烈采用意愿,归因于竞争压力。本研究提供了基于实践者的实证分析,提出了面向人类中心、操作安全的大模型集成设计要求。
原文摘要 · Abstract (English)
Security Operations Centers (SOCs) process large volumes of security events, requiring analysts to accurately detect and assess ongoing cyberattacks under time pressure. Recent advances in Large Language Models (LLMs) suggest potential benefits for security operations, yet their practical suitability for real-world SOC workflows remains poorly understood. To address this gap, we conducted 25 semi-structured interviews with SOC practitioners who had prior experience with LLMs, complemented by interactive scenarios to anticipate challenges and identify opportunities for the responsible integration of LLM-based tools into SOC workflows. We identified 15 LLM use cases grouped into six functional categories. While LLMs are valued for automating repetitive, low-level tasks such as report automation, practitioners rate high-impact tasks such as incident analysis as not yet feasible, reporting limitations in technical depth, context awareness, and organization-specific knowledge. They locate these limitations less in the models than in the readiness of their SOCs and human factors driving over-reliance. Despite concerns, practitioners express a strong willingness to adopt LLMs, describing competitive pressure that leaves few alternatives. This work contributes an empirical, practitioner-driven analysis of LLM use across SOC roles and organizations and derives concrete design and integration requirements for human-centered, operationally safe LLM-assisted security operations.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。