AI-Driven Security Alert Screening and Alert Fatigue Mitigation in Security Operations Centers: A Survey
Fuente:
arXiv
Salvato in:
| Autori principali: | , , , , |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2026
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866914578894422016 |
|---|---|
| author | Ndichu, Samuel Ban, Tao Ozawa, Seiichi Takahashi, Takeshi Inoue, Daisuke |
| author_facet | Ndichu, Samuel Ban, Tao Ozawa, Seiichi Takahashi, Takeshi Inoue, Daisuke |
| contents | Security alert screening is the downstream task of filtering, prioritizing, correlating, and contextualizing alerts for analyst attention in Security Operations Centers. This survey reviews artificial-intelligence-driven alert screening and alert-fatigue mitigation from 2015 to 2026. We synthesize 119 records, including 87 core studies, into a four-stage workflow taxonomy covering filtering, triage, correlation, and generative augmentation. We find persistent gaps in operational validation, adversarial robustness, cross-environment generalization, and evaluation practice. The survey concludes with a research agenda toward trustworthy Cognitive Security Operations Centers. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2605_08316 |
| institution | arXiv |
| publishDate | 2026 |
| record_format | arxiv |
| spellingShingle | AI-Driven Security Alert Screening and Alert Fatigue Mitigation in Security Operations Centers: A Survey Ndichu, Samuel Ban, Tao Ozawa, Seiichi Takahashi, Takeshi Inoue, Daisuke Cryptography and Security D.4.6; I.2.0 Security alert screening is the downstream task of filtering, prioritizing, correlating, and contextualizing alerts for analyst attention in Security Operations Centers. This survey reviews artificial-intelligence-driven alert screening and alert-fatigue mitigation from 2015 to 2026. We synthesize 119 records, including 87 core studies, into a four-stage workflow taxonomy covering filtering, triage, correlation, and generative augmentation. We find persistent gaps in operational validation, adversarial robustness, cross-environment generalization, and evaluation practice. The survey concludes with a research agenda toward trustworthy Cognitive Security Operations Centers. |
| title | AI-Driven Security Alert Screening and Alert Fatigue Mitigation in Security Operations Centers: A Survey |
| topic | Cryptography and Security D.4.6; I.2.0 |
| url | https://arxiv.org/abs/2605.08316 |