Beyond the Hype: Evaluating LLM Integration and Practical Limitations in Security Operation Centers

📅 2026-08-17
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究通过半结构化访谈探讨了LLM在安全运营中心的应用局限,提出成熟度评估标准和研究议程以提高模型的可审计性和透明度。
📝 Abstract
Large Language Models (LLMs) are increasingly being explored within Security Operation Centers (SOCs) to support text-heavy analytical work such as alert contextualization, incident summarization, and drafting investigative artifacts. Despite this interest, practitioners describe critical operational concerns, most notably hallucinations (plausible but incorrect outputs), opaque reasoning, and the verification effort required to safely use model-generated content in security workflows. In this paper, we present findings from semi-structured interviews with 20 SOC practitioners spanning frontline analysts, SOC managers, and tool developers. Participants report perceived time savings for low-stakes tasks that are quickly verifiable (e.g., summarizing logs or drafting initial investigative leads), but they consistently frame LLM outputs as preliminary drafts and suggestions rather than decision-grade conclusions. Participants also describe limited trust in LLMs for high-stakes security decisions due to unreliable outputs and unclear model reasoning, and they report relying primarily on ad-hoc verification norms and continuous human oversight rather than standardized mitigation procedures. Based on these interview-grounded accounts, we introduce a maturity rubric to characterize readiness for LLM integration and outline a research agenda emphasizing auditability and transparent explanation mechanisms to support safer adoption in SOC workflows.
Problem

Research questions and friction points this paper is trying to address.

Large Language Models
Security Operation Centers
hallucinations
opaque reasoning
verification effort
Innovation

Methods, ideas, or system contributions that make the work stand out.

Large Language Models
Security Operation Centers
Auditability
Transparent Explanation Mechanisms
Maturity Rubric
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
E
Elnaz Rabieinejad
Cyber Science Lab, Canada Cyber Foundry, University of Guelph, Guelph, ON, Canada
Ali Dehghantanha
Ali Dehghantanha
Canada Research Chair in Cybersecurity & Threat Intelligence, Cyber Science Lab,University of Guelph
Cyber Threat IntelligenceCyber Threat HuntingAI SecurityAutonomous Cybersecurity
Fattane Zarrinkalam
Fattane Zarrinkalam
University of Guelph
Information RetrievalSocial Media Mining
S
Sarina Dastgerdy
Cyber Science Lab, Canada Cyber Foundry, University of Guelph, Guelph, ON, Canada