🤖 AI Summary
Security Operations Centers (SOCs) face critical challenges including alert overload, heavy reliance on expert analysts, delayed incident response, and low utilization of threat intelligence. To address these issues, this paper presents the first systematic survey of large language models (LLMs) in SOC contexts, establishing a structured research framework that delineates LLM capabilities, practical deployment challenges, and future evolutionary trajectories—thereby filling a significant academic gap. Methodologically, we propose an LLM-powered architecture integrating automated log analysis, intelligent alert triage, and context-aware knowledge support, synergizing natural language processing, generative AI, threat intelligence modeling, and automated response orchestration. Our approach demonstrably optimizes SOC workflows in terms of scalability, accuracy, and operational efficiency. The contributions include a comprehensive, practitioner-informed taxonomy of LLM applications in cybersecurity operations, actionable insights for researchers and practitioners, and foundational guidance toward AI-native security operations—advancing both theoretical understanding and real-world implementation.
📝 Abstract
Large Language Models (LLMs) have emerged as powerful tools capable of understanding and generating human-like text, offering transformative potential across diverse domains. The Security Operations Center (SOC), responsible for safeguarding digital infrastructure, represents one of these domains. SOCs serve as the frontline of defense in cybersecurity, tasked with continuous monitoring, detection, and response to incidents. However, SOCs face persistent challenges such as high alert volumes, limited resources, high demand for experts with advanced knowledge, delayed response times, and difficulties in leveraging threat intelligence effectively. In this context, LLMs can offer promising solutions by automating log analysis, streamlining triage, improving detection accuracy, and providing the required knowledge in less time. This survey systematically explores the integration of generative AI and more specifically LLMs into SOC workflow, providing a structured perspective on its capabilities, challenges, and future directions. We believe that this survey offers researchers and SOC managers a broad overview of the current state of LLM integration within academic study. To the best of our knowledge, this is the first comprehensive study to examine LLM applications in SOCs in details.