Towards AI-Driven Human-Machine Co-Teaming for Adaptive and Agile Cyber Security Operation Centers

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Albanese, Massimiliano, Ou, Xinming, Lybarger, Kevin, Lende, Daniel, Goldgof, Dmitry
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913829421580288
author Albanese, Massimiliano
Ou, Xinming
Lybarger, Kevin
Lende, Daniel
Goldgof, Dmitry
author_facet Albanese, Massimiliano
Ou, Xinming
Lybarger, Kevin
Lende, Daniel
Goldgof, Dmitry
contents Security Operations Centers (SOCs) face growing challenges in managing cybersecurity threats due to an overwhelming volume of alerts, a shortage of skilled analysts, and poorly integrated tools. Human-AI collaboration offers a promising path to augment the capabilities of SOC analysts while reducing their cognitive overload. To this end, we introduce an AI-driven human-machine co-teaming paradigm that leverages large language models (LLMs) to enhance threat intelligence, alert triage, and incident response workflows. We present a vision in which LLM-based AI agents learn from human analysts the tacit knowledge embedded in SOC operations, enabling the AI agents to improve their performance on SOC tasks through this co-teaming. We invite SOCs to collaborate with us to further develop this process and uncover replicable patterns where human-AI co-teaming yields measurable improvements in SOC productivity.
format Preprint
id arxiv_https___arxiv_org_abs_2505_06394
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Towards AI-Driven Human-Machine Co-Teaming for Adaptive and Agile Cyber Security Operation Centers
Albanese, Massimiliano
Ou, Xinming
Lybarger, Kevin
Lende, Daniel
Goldgof, Dmitry
Cryptography and Security
Artificial Intelligence
Security Operations Centers (SOCs) face growing challenges in managing cybersecurity threats due to an overwhelming volume of alerts, a shortage of skilled analysts, and poorly integrated tools. Human-AI collaboration offers a promising path to augment the capabilities of SOC analysts while reducing their cognitive overload. To this end, we introduce an AI-driven human-machine co-teaming paradigm that leverages large language models (LLMs) to enhance threat intelligence, alert triage, and incident response workflows. We present a vision in which LLM-based AI agents learn from human analysts the tacit knowledge embedded in SOC operations, enabling the AI agents to improve their performance on SOC tasks through this co-teaming. We invite SOCs to collaborate with us to further develop this process and uncover replicable patterns where human-AI co-teaming yields measurable improvements in SOC productivity.
title Towards AI-Driven Human-Machine Co-Teaming for Adaptive and Agile Cyber Security Operation Centers
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2505.06394