paper-with-me

Papers

AI-Driven Guided Response for Security Operation Centers with Microsoft Copilot for Security

2024-07-12 · Scott Freitas, Jovan Kalajdjieski, Amir Gharib, Robert McCann

Security operation centers contend with a constant stream of security incidents, ranging from straightforward to highly complex. To address this, we developed Microsoft Copilot for Security Guided Response (CGR), an industry-scale ML architecture that guides security analysts across three key tasks -- (1) investigation, providing essential historical context by identifying similar incidents; (2) triaging to ascertain the nature of the incident -- whether it is a true positive, false positive, or benign positive; and (3) remediation, recommending tailored containment actions. CGR is integrated into the Microsoft Defender XDR product and deployed worldwide, generating millions of recommendations across thousands of customers. Our extensive evaluation, incorporating internal evaluation, collaboration with security experts, and customer feedback, demonstrates that CGR delivers high-quality recommendations across all three tasks. We provide a comprehensive overview of the CGR architecture, setting a precedent as the first cybersecurity company to openly discuss these capabilities in such depth. Additionally, we release GUIDE, the largest public collection of real-world security incidents, spanning 13M evidences across 1M incidents annotated with ground-truth triage labels by customer security analysts. This dataset represents the first large-scale cybersecurity resource of its kind, supporting the development and evaluation of guided response systems and beyond.

📄 PDF Abstract BibTeX arXiv:2407.09017

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Towards AI-Driven Human-Machine Co-Teaming for Adaptive and Agile Cyber Security Operation Centers

2025-05-09 · Massimiliano Albanese, Xinming Ou, Kevin Lybarger, Daniel Lende 외

Security Operations Centers (SOCs) face growing challenges in managing cybersecurity threats due to an overwhelming volume of alerts, a shortage of skilled analysts, and poorly integrated tools. Human-AI collaboration of…

AgentSOC: A Multi-Layer Agentic AI Framework for Security Operations Automation

2026-04-22 · Joyjit Roy, Samaresh Kumar Singh arxiv

Security Operations Centers (SOCs) increasingly encounter difficulties in correlating heterogeneous alerts, interpreting multi-stage attack progressions, and selecting safe and effective response actions. This study intr…

IRSDA: An Agent-Orchestrated Framework for Enterprise Intrusion Response

2025-11-24 · Damodar Panigrahi, Raj Patel, Shaswata Mitra, Sudip Mittal 외 arxiv

Modern enterprise systems face escalating cyber threats that are increasingly dynamic, distributed, and multi-stage in nature. Traditional intrusion detection and response systems often rely on static rules and manual wo…

Intrusion Detection

A Unified Framework for Human AI Collaboration in Security Operations Centers with Trusted Autonomy

2025-05-29 · Ahmad Mohsin, Helge Janicke, Ahmed Ibrahim, Iqbal H. Sarker 외

This article presents a structured framework for Human-AI collaboration in Security Operations Centers (SOCs), integrating AI autonomy, trust calibration, and Human-in-the-loop decision making. Existing frameworks in SOC…

Decision Making

Survey Perspective: The Role of Explainable AI in Threat Intelligence

2025-03-03 · Nidhi Rastogi, Devang Dhanuka, Amulya Saxena, Pranjal Mairal 외

The increasing reliance on AI-based security tools in Security Operations Centers (SOCs) has transformed threat detection and response, yet analysts frequently struggle with alert overload, false positives, and lack of c…

Decision MakingNavigateSurvey