paper-with-me

홈 › Papers

From Chasing Ghosts to Missed Attacks: Perspectives and Perceptions of SOC Practitioners on LLM Integration, Risks, and Readiness

2026-08-01 · Jonas Thurner, Nadine Jost, Stefan Albert Horstmann, Fabian Ising, Lea Groeber, Alena Naiakshina, Sebastian Schinzel arxiv

Security Operations Centers (SOCs) process large volumes of security events, requiring analysts to accurately detect and assess ongoing cyberattacks under time pressure. Recent advances in Large Language Models (LLMs) suggest potential benefits for security operations, yet their practical suitability for real-world SOC workflows remains poorly understood. To address this gap, we conducted 25 semi-structured interviews with SOC practitioners who had prior experience with LLMs, complemented by interactive scenarios to anticipate challenges and identify opportunities for the responsible integration of LLM-based tools into SOC workflows. We identified 15 LLM use cases grouped into six functional categories. While LLMs are valued for automating repetitive, low-level tasks such as report automation, practitioners rate high-impact tasks such as incident analysis as not yet feasible, reporting limitations in technical depth, context awareness, and organization-specific knowledge. They locate these limitations less in the models than in the readiness of their SOCs and human factors driving over-reliance. Despite concerns, practitioners express a strong willingness to adopt LLMs, describing competitive pressure that leaves few alternatives. This work contributes an empirical, practitioner-driven analysis of LLM use across SOC roles and organizations and derives concrete design and integration requirements for human-centered, operationally safe LLM-assisted security operations.

📄 PDF Abstract BibTeX arXiv:2608.00672

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Chasing Ghosts: A Simulation-to-Real Olfactory Navigation Stack with Optional Vision Augmentation

2026-02-23 · Kordel K. France, Ovidiu Daescu, Latifur Khan, Rohith Peddi arxiv

Autonomous odor source localization remains a challenging problem for aerial robots due to turbulent airflow, sparse and delayed sensory signals, and strict payload and compute constraints. While prior unmanned aerial ve…

Toward Explainable Users: Using NLP to Enable AI to Understand Users' Perceptions of Cyber Attacks

2021-06-03 · Faranak Abri, Luis Felipe Gutierrez, Chaitra T. Kulkarni, Akbar Siami Namin 외

To understand how end-users conceptualize consequences of cyber security attacks, we performed a card sorting study, a well-known technique in Cognitive Sciences, where participants were free to group the given consequen…

Sentence

GhostShell: Streaming LLM Function Calls for Concurrent Embodied Programming

2025-08-07 · Jian Gong, Youwei Huang, Bo Yuan, Ming Zhu 외 arxiv

We present GhostShell, a novel approach that leverages Large Language Models (LLMs) to enable streaming and concurrent behavioral programming for embodied systems. In contrast to conventional methods that rely on pre-sch…

Ask LLMs Directly, "What shapes your bias?": Measuring Social Bias in Large Language Models

2024-06-06 · Jisu Shin, Hoyun Song, Huije Lee, Soyeong Jeong 외

Social bias is shaped by the accumulation of social perceptions towards targets across various demographic identities. To fully understand such social bias in large language models (LLMs), it is essential to consider the…

Chasing Ghosts: Competing with Stateful Policies

2014-07-29 · Uriel Feige, Tomer Koren, Moshe Tennenholtz

We consider sequential decision making in a setting where regret is measured with respect to a set of stateful reference policies, and feedback is limited to observing the rewards of the actions performed (the so called …

AttributeDecision MakingLEMMASequential Decision Making