{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T17:38:46Z","timestamp":1786815526560,"version":"3.56.0"},"reference-count":109,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2025,11,5]],"date-time":"2025-11-05T00:00:00Z","timestamp":1762300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"California State University, San Bernardino, School of Computer Science and Engineering"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>The increasing volume, velocity, and sophistication of cyber threats have placed immense pressure on modern Security Operations Centers (SOCs). Traditional rule-based and manual processes are proving insufficient, leading to alert fatigue, delayed responses, high false-positive rates, analyst dependency, and escalating operational costs. Recent advancements in Artificial Intelligence (AI) offer new opportunities to transform SOC workflows through automation and augmentation. Large Language Models (LLMs) and autonomous AI agents have shown strong potential in enhancing capabilities such as log summarization, alert triage, threat intelligence, incident response, report generation, asset discovery, and vulnerability management. This paper reviews recent developments in the application of LLMs and AI agents across these SOC functions, introducing a taxonomy that organizes their roles and capabilities within operational pipelines. While these technologies improve detection accuracy, response time, and analyst support, challenges persist, including model interpretability, adversarial robustness, integration with legacy systems, and the risk of hallucinations or data leakage. A detailed capability-maturity model outlines the levels of integration with SOC tasks. This survey synthesizes trends, identifies persistent limitations, and outlines future directions for trustworthy, explainable, and safe AI integration in SOC environments.<\/jats:p>","DOI":"10.3390\/jcp5040095","type":"journal-article","created":{"date-parts":[[2025,11,5]],"date-time":"2025-11-05T17:06:06Z","timestamp":1762362366000},"page":"95","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":27,"title":["AI-Augmented SOC: A Survey of LLMs and Agents for Security Automation"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-1600-9153","authenticated-orcid":false,"given":"Siddhant","family":"Srinivas","sequence":"first","affiliation":[{"name":"School of Computer Science & Engineering, California State University, San Bernardino, 5500 University Parkway, San Bernardino, CA 92407, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Brandon","family":"Kirk","sequence":"additional","affiliation":[{"name":"School of Computer Science & Engineering, California State University, San Bernardino, 5500 University Parkway, San Bernardino, CA 92407, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Julissa","family":"Zendejas","sequence":"additional","affiliation":[{"name":"School of Computer Science & Engineering, California State University, San Bernardino, 5500 University Parkway, San Bernardino, CA 92407, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Espino","sequence":"additional","affiliation":[{"name":"School of Computer Science & Engineering, California State University, San Bernardino, 5500 University Parkway, San Bernardino, CA 92407, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Matthew","family":"Boskovich","sequence":"additional","affiliation":[{"name":"School of Computer Science & Engineering, California State University, San Bernardino, 5500 University Parkway, San Bernardino, CA 92407, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Abdul","family":"Bari","sequence":"additional","affiliation":[{"name":"School of Computer Science & Engineering, California State University, San Bernardino, 5500 University Parkway, San Bernardino, CA 92407, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Khalil","family":"Dajani","sequence":"additional","affiliation":[{"name":"School of Computer Science & Engineering, California State University, San Bernardino, 5500 University Parkway, San Bernardino, CA 92407, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-5671-7277","authenticated-orcid":false,"given":"Nabeel","family":"Alzahrani","sequence":"additional","affiliation":[{"name":"School of Computer Science & Engineering, California State University, San Bernardino, 5500 University Parkway, San Bernardino, CA 92407, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,11,5]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"360","DOI":"10.1109\/OJCS.2025.3536800","article-title":"The Rise of Cognitive SOCs: A Systematic Literature Review on AI Approaches","volume":"6","author":"Binbeshr","year":"2025","journal-title":"IEEE Open J. Comput. Soc."},{"key":"ref_2","unstructured":"Hassanin, M., and Moustafa, N. (2024). A Comprehensive Overview of Large Language Models (LLMs) for Cyber Defences: Opportunities and Directions. arXiv."},{"key":"ref_3","unstructured":"Mohsin, A., Janicke, H., Ibrahim, A., Sarker, I.H., and Camtepe, S. (2025). A Unified Framework for Human AI Collaboration in Security Operations Centers with Trusted Autonomy. arXiv."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Chigurupati, M., Malviya, R.K., Toorpu, A.R., and Anand, K. (2025, January 5\u20137). AI Agents for Cloud Reliability: Autonomous Threat Detection and Mitigation Aligned with Site Reliability Engineering Principles. Proceedings of the 2025 IEEE 4th International Conference on AI in Cybersecurity (ICAIC), Houston, TX, USA.","DOI":"10.1109\/ICAIC63015.2025.10849322"},{"key":"ref_5","unstructured":"Song, C., Ma, L., Zheng, J., Liao, J., Kuang, H., and Yang, L. (2024). Audit-LLM: Multi-Agent Collaboration for Log-based Insider Threat Detection. arXiv."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"80218","DOI":"10.1109\/ACCESS.2023.3300381","article-title":"From ChatGPT to ThreatGPT: Impact of Generative AI in Cybersecurity and Privacy","volume":"11","author":"Gupta","year":"2023","journal-title":"IEEE Access"},{"key":"ref_7","unstructured":"IEEE Xplore (2025). IEEE Xplore Digital Library, IEEE. Available online: https:\/\/ieeexplore.ieee.org\/."},{"key":"ref_8","unstructured":"arXiv (2025). arXiv.org e-Print Archive, Cornell University. Available online: https:\/\/arxiv.org\/."},{"key":"ref_9","unstructured":"ACM Digital Library (2025, June 04). ACM Digital Library, Association for Computing Machinery. Available online: https:\/\/dl.acm.org\/."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Zhong, A., Mo, D., Liu, G., Liu, J., Lu, Q., Zhou, Q., Wu, J., Li, Q., and Wen, Q. (2024, January 25\u201329). LogParser-LLM: Advancing efficient log parsing with large language models. Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining (KDD \u201924), Barcelona, Spain.","DOI":"10.1145\/3637528.3671810"},{"key":"ref_11","unstructured":"Huang, J., Jiang, Z., Chen, Z., and Lyu, M.R. (2024). LUNAR: Unsupervised LLM-based Log Parsing. arXiv."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Balasubramanian, P., Seby, J., and Kostakos, P. (2024). CYGENT: A cybersecurity conversational agent with log summarization powered by GPT-3. arXiv.","DOI":"10.1109\/AIIoT58432.2024.10574658"},{"key":"ref_13","unstructured":"Liu, X., Liang, J., Yan, Q., Jang, J., Mao, S., Ye, M., Jia, J., and Xi, Z. (2025). CyLens: Towards Reinventing Cyber Threat Intelligence in the Paradigm of Agentic Large Language Models. arXiv."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Ma, Z., Kim, D.J., and Chen, T.-H.P. (2024). LibreLog: Accurate and efficient unsupervised log parsing using open-source large language models. arXiv.","DOI":"10.1109\/ICSE55347.2025.00103"},{"key":"ref_15","unstructured":"Akhtar, S., Khan, S., and Parkinson, S. (2025). LLM-based event log analysis techniques: A survey. arXiv."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Ma, Z., Chen, A.R., Kim, D.J., Chen, T.-H., and Wang, S. (2024, January 14\u201320). LLMParser: An Exploratory Study on Using Large Language Models for Log Parsing. Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering, Lisbon, Portugal.","DOI":"10.1145\/3597503.3639150"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Fieblinger, R., Alam, T., and Rastogi, N. (2024). Actionable Cyber Threat Intelligence using Knowledge Graphs and Large Language Models. arXiv.","DOI":"10.1109\/EuroSPW61312.2024.00018"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Liu, Y., Tao, S., Meng, W., Wang, J., Ma, W., Chen, Y., Zhao, Y., Yang, H., and Jiang, Y. (2024, January 15\u201316). Interpretable Online Log Analysis Using Large Language Models with Prompt Strategies. Proceedings of the 32nd IEEE\/ACM International Conference on Program Comprehension (ICPC \u201924), Lisbon, Portugal.","DOI":"10.1145\/3643916.3644408"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Gupta, P., Bhukar, K., Kumar, H., Nagar, S., Mohapatra, P., and Kar, D. (2025, January 5\u20139). LogAn: An LLM-Based Log Analytics Tool with Causal Inferencing. Proceedings of the 16th ACM\/SPEC International Conference on Performance Engineering Companion (ICPE Companion), Toronto, ON, Canada.","DOI":"10.1145\/3680256.3721246"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Al Siam, A., Hassan, M., and Bhuiyan, T. (2025, January 5\u20137). Artificial Intelligence for Cybersecurity: A State of the Art. Proceedings of the 2025 IEEE 4th International Conference on AI in Cybersecurity (ICAIC), Houston, TX, USA.","DOI":"10.1109\/ICAIC63015.2025.10848980"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Jiang, Z., Liu, J., Chen, Z., Li, Y., Huang, J., Huo, Y., He, P., Gu, J., and Lyu, M.R. (2023). LILAC: Log Parsing using LLMs with Adaptive Parsing Cache. arXiv.","DOI":"10.1145\/3643733"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Karlsen, E., Luo, X., Zincir-Heywood, N., and Heywood, M. (2023). Heywood, Benchmarking Large Language Models for Log Analysis, Security, and Interpretation. arXiv.","DOI":"10.1007\/s10922-024-09831-x"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Fayyazi, R., Taghdimi, R., and Yang, S.J. (2024). Advancing TTP Analysis: Harnessing the Power of Large Language Models with Retrieval-Augmented Generation. arXiv.","DOI":"10.1109\/ACSACW65225.2024.00036"},{"key":"ref_24","unstructured":"Zhang, H., Huang, J., Mei, K., Yao, Y., Wang, Z., Zhan, C., Wang, H., and Zhang, Y. (2024). Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents. arXiv."},{"key":"ref_25","unstructured":"Liu, X., Yu, F., Li, X., Yan, G., Yang, P., and Xi, Z. (2025). Benchmarking LLMs in an Embodied Environment for Blue Team Threat Hunting. arXiv."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Loumachi, F.Y., Ghanem, M.C., and Ferrag, M.A. (2024). GenDFIR: Advancing Cyber Incident Timeline Analysis Through Retrieval Augmented Generation and Large Language Models. arXiv.","DOI":"10.20944\/preprints202412.2516.v1"},{"key":"ref_27","unstructured":"Ali, T., and Kostakos, P. (2023). HuntGPT: Integrating Machine Learning-Based Anomaly Detection and Explainable AI with Large Language Models (LLMs). arXiv."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Cheng, Y., Bajaber, O., Tsegai, S.A., Song, D., and Gao, P. (2025). CTINexus: Automatic Cyber Threat Intelligence Knowledge Graph Construction Using LLMs. arXiv.","DOI":"10.1109\/EuroSP63326.2025.00057"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3695462","article-title":"Alert Prioritisation in Security Operations Centres: A Systematic Survey on Criteria and Methods","volume":"57","author":"Jalalvand","year":"2024","journal-title":"ACM Comput. Surv."},{"key":"ref_30","unstructured":"Shah, S., and Parast, F.K. (2024). Parast, AI-Driven Cyber Threat Intelligence Automation. arXiv."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Cuong Nguyen, H., Tariq, S., Baruwal Chhetri, M., and Quoc Vo, B. (May, January 28). Towards Effective Identification of Attack Techniques in Cyber Threat Intelligence Reports Using Large Language Models. Proceedings of the Companion of the ACM on Web Conference 2025 (WWW Companion\u201925), Sydney, Australia.","DOI":"10.1145\/3701716.3715469"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Jin, P., Zhang, S., Ma, M., Li, H., Kang, Y., Li, L., Liu, Y., Qiao, B., Zhang, C., and Zhao, P. (2023). Assess and Summarize: Improve Outage Understanding with Large Language Models. arXiv.","DOI":"10.1145\/3611643.3613891"},{"key":"ref_33","unstructured":"de Witt, C.S. (2025). Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents. arXiv."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Sharma, A.N., Akbar, K.A., Thuraisingham, B., and Khan, L. (2025, January 6). Enhancing Security Insights with KnowGen-RAG: Combining Knowledge Graphs, LLMs, and Multimodal Interpretability. Proceedings of the 10th ACM International Workshop on Security and Privacy Analytics, Pittsburgh, PA, USA.","DOI":"10.1145\/3716815.3729012"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Daniel, N., Kaiser, F.K., Giladi, S., Sharabi, S., Moyal, R., Shpolyansky, S., Murilllo, A., Elyashar, A., and Puzis, R. (2024). Labeling NIDS Rules with MITRE ATT&CK Techniques: Machine Learning vs. Large Language Models. arXiv.","DOI":"10.3390\/bdcc9020023"},{"key":"ref_36","unstructured":"Froudakis, E., Avgetidis, A., Frankum, S.T., Perdisci, R., Antonakakis, M., and Keromytis, A. (2025). Uncovering Reliable Indicators: Improving IoC Extraction from Threat Reports. arXiv."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Alnahdi, A., and Narain, S. (2024, January 28\u201331). Towards Transparent Intrusion Detection: A Coherence-Based Framework in Explainable AI Integrating Large Language Models. Proceedings of the 2024 IEEE 6th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA), Washington, DC, USA.","DOI":"10.1109\/TPS-ISA62245.2024.00020"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Jain, S., Gupta, A., and Neha, K. (2024, January 8\u201311). AI Enhanced Ticket Management System for Optimized Support. Proceedings of the 4th International Conference on AI-ML Systems (AIMLSystems 2024), Baton Rouge, LA, USA.","DOI":"10.1145\/3703412.3703433"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Pei, C., Wang, Z., Liu, F., Li, Z., Liu, Y., He, X., Kang, R., Zhang, T., Chen, J., and Li, J. (May, January 28). Flow-of-Action: SOP Enhanced LLM-Based Multi-Agent System for Root Cause Analysis. Proceedings of the Companion ACM Web Conf. 2025 (WWW Companion\u201925), Sydney, NSW, Australia.","DOI":"10.1145\/3701716.3715225"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Chen, Y., Xie, H., Ma, M., Kang, Y., Gao, X., Shi, L., Cao, Y., Gao, X., Fan, H., and Wen, M. (2023). Automatic Root Cause Analysis via Large Language Models for Cloud Incidents. arXiv.","DOI":"10.1145\/3627703.3629553"},{"key":"ref_41","unstructured":"Yang, Y., Deng, Y., Xiong, Y., Li, B., Xu, H., and Cheng, P. (2025). AidAI: Automated Incident Diagnosis for AI Workloads in the Cloud. arXiv."},{"key":"ref_42","unstructured":"Liu, Z., Benge, C., and Jiang, S. (2023). Ticket-BERT: Labeling incident management tickets with language models. arXiv."},{"key":"ref_43","unstructured":"Li, C., Zhu, Z., He, J., and Zhang, X. (2025). RedChronos: A Large Language Model-Based Log Analysis System for Insider Threat Detection in Enterprises. arXiv."},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Liu, F., He, X., Zhang, T., Chen, J., Li, Y., Yi, L., Zhang, H., Wu, G., and Shi, R. (2025). TickIt: Leveraging Large Language Models for Automated Ticket Escalation. arXiv.","DOI":"10.1145\/3696630.3728558"},{"key":"ref_45","unstructured":"Nong, Y., Yang, H., Cheng, L., Hu, H., and Cai, H. (2025, January 23\u201326). APPATCH: Automated Adaptive Prompting Large Language Models for Real-World Software Vulnerability Patching. Proceedings of the 2025 Network and Distributed System Security Symposium (NDSS 2025), San Diego, CA, USA."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Lin, J., and Mohaisen, D. (2025). Evaluating Large Language Models in Vulnerability Detection Under Variable Context Windows. arXiv.","DOI":"10.1109\/ICMLA61862.2024.00173"},{"key":"ref_47","unstructured":"Lin, X., Zhang, J., Deng, G., Liu, T., Zhang, T., Guo, Q., and Chen, R. (2025). IRCopilot: Automated Incident Response with Large Language Models. arXiv."},{"key":"ref_48","unstructured":"Liu, Z. (2024). Multi-Agent Collaboration in Incident Response with Large Language Models. arXiv."},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Perrina, F., Marchiori, F., Conti, M., and Verde, N.V. (2023). AGIR: Automating Cyber Threat Intelligence Reporting with Natural Language Generation. arXiv.","DOI":"10.1109\/BigData59044.2023.10386116"},{"key":"ref_50","unstructured":"Wudali, P.N., Kravchik, M., Malul, E., Gandhi, P.A., Elovici, Y., and Shabtai, A. (2025). Rule-ATT&CK Mapper (RAM): Mapping SIEM Rules to TTPs Using LLMs. arXiv."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Goel, D., Husain, F., Singh, A., Ghosh, S., Parayil, A., Bansal, C., Zhang, X., and Rajmohan, S. (2024). X-lifecycle Learning for Cloud Incident Management using LLMs. arXiv.","DOI":"10.1145\/3663529.3663861"},{"key":"ref_52","unstructured":"Albanese, M., Ou, X., Lybarger, K., Lende, D., and Goldgof, D. (2025). Towards AI-driven human-machine co-teaming for adaptive and agile cyber security operation centers. arXiv."},{"key":"ref_53","unstructured":"Patel, D., Lin, S., Rayfield, J., Zhou, N., Vaculin, R., Martinez, N., O\u2019donncha, F., and Kalagnanam, J. (2025). AssetOpsBench: Benchmarking AI Agents for Task Automation in Industrial Asset Operations and Maintenance. arXiv."},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Mitra, S., Neupane, S., Chakraborty, T., Mittal, S., Piplai, A., Gaur, M., and Rahimi, S. (2025). LocalIntel: Generating organizational threat intelligence from global and local cyber knowledge. arXiv.","DOI":"10.1007\/978-3-031-87496-3_5"},{"key":"ref_55","unstructured":"Chopra, S., Ahmad, H., Goel, D., and Szabo, C. (2025). ChatNVD: Advancing Cybersecurity Vulnerability Assessment with Large Language Models. arXiv."},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"CRondanini, C., Carminati, B., Ferrari, E., Kundu, A., and Gaudiano, A. (2025). Malware Detection at the Edge with Lightweight LLMs: A Performance Evaluation. arXiv.","DOI":"10.1145\/3769681"},{"key":"ref_57","unstructured":"Jin, Y., Li, C., Fan, P., Liu, P., Li, X., Liu, C., and Qiu, W. (2025). LLM-BSCVM: An LLM-based blockchain smart contract vulnerability management framework. arXiv."},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"56861","DOI":"10.1109\/ACCESS.2025.3554960","article-title":"LLM-Driven, Self-Improving Framework for Security Test Automation: Leveraging Karate DSL for Augmented API Resilience","volume":"13","author":"Pasca","year":"2025","journal-title":"IEEE Access"},{"key":"ref_59","unstructured":"Torkamani, M.J., Ng, J., Mehrotra, N., Chandramohan, M., Krishnan, P., and Purandare, R. (2025). Streamlining security vulnerability triage with large language models. arXiv."},{"key":"ref_60","doi-asserted-by":"crossref","unstructured":"Applebaum, A., Dennler, C., Dwyer, P., Moskowitz, M., Nguyen, H., Nichols, N., Park, N., Rachwalski, P., Rau, F., and Webster, A. (2022, January 11). Bridging Automated to Autonomous Cyber Defense. Proceedings of the 15th ACM Workshop on Artificial Intelligence and Security, Los Angeles, CA, USA.","DOI":"10.1145\/3560830.3563732"},{"key":"ref_61","doi-asserted-by":"crossref","unstructured":"Alam, M.T., Bhusal, D., Nguyen, L., and Rastogi, N. (2024). CTIBench: A Benchmark for Evaluating LLMs in Cyber Threat Intelligence. arXiv.","DOI":"10.52202\/079017-1607"},{"key":"ref_62","unstructured":"Xiao, Y., Le, V.H., and Zhang, H. (2024). Stronger, Faster, and Cheaper Log Parsing with LLMs. arXiv."},{"key":"ref_63","doi-asserted-by":"crossref","first-page":"103805","DOI":"10.1016\/j.cose.2024.103805","article-title":"LogPr\u00e9cis: Unleashing language models for automated malicious log analysis","volume":"141","author":"Boffa","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_64","doi-asserted-by":"crossref","first-page":"19162","DOI":"10.1109\/ACCESS.2025.3532951","article-title":"Empowering Security Operation Center with Artificial Intelligence and Machine Learning\u2014A Systematic Literature Review","volume":"13","author":"Khayat","year":"2025","journal-title":"IEEE Access"},{"key":"ref_65","unstructured":"Aung, Y.L., Christian, I., Dong, Y., Ye, X., Chattopadhyay, S., Zhou, J., Chattopadhyay, S., and Zhou, J. (2025). Generative AI for Internet of Things Security: Challenges and Opportunities. arXiv."},{"key":"ref_66","unstructured":"Tran, K.T., Dao, D., Nguyen, M.D., Pham, Q.V., O\u2019Sullivan, B., and Nguyen, H.D. (2025). Nguyen, Multi-Agent Collaboration Mechanisms: A Survey of LLMs. arXiv."},{"key":"ref_67","doi-asserted-by":"crossref","unstructured":"Jin, H., Papadimitriou, G., Raghavan, K., Zuk, P., Balaprakash, P., Wang, C., Mandal, A., and Deelman, E. (2024). Large Language Models for Anomaly Detection in Computational Workflows: From Supervised Fine-Tuning to In-Context Learning. arXiv.","DOI":"10.1109\/SC41406.2024.00098"},{"key":"ref_68","unstructured":"Wong, M.Y., Valakuzhy, K., Ahamad, M., Blough, D., and Monrose, F. (2024, January 4\u20138). Understanding LLMs Ability to Aid Malware Analysts in Bypassing Evasion Techniques. Proceedings of the Companion 26th International Conference on Multimodal Interaction, San Jose, Costa Rica."},{"key":"ref_69","first-page":"22","article-title":"Towards Human-AI Teaming to Mitigate Alert Fatigue in Security Operations Centres","volume":"24","author":"Chhetri","year":"2024","journal-title":"ACM Trans. Internet Technol."},{"key":"ref_70","doi-asserted-by":"crossref","unstructured":"Freitas, S., Kalajdjieski, J., Gharib, A., and McCann, R. (May, January 28). AI-Driven Guided Response for Security Operation Centers with Microsoft Copilot for Security. Proceedings of the Companion ACM Web Conference 2025 (WWW Companion\u201925), Sydney, NSW, Australia.","DOI":"10.1145\/3701716.3715209"},{"key":"ref_71","doi-asserted-by":"crossref","unstructured":"Kim, M., Wang, J., Moore, K., Goel, D., Wang, D., Mohsin, A., Ibrahim, A., Doss, R., Camtepe, S., and Janicke, H. (May, January 28). CyberAlly: Leveraging LLMs and Knowledge Graphs to Empower Cyber Defenders, Companion. Proceedings of the ACM on Web Conference 2025, New York, NY, USA.","DOI":"10.1145\/3701716.3715171"},{"key":"ref_72","doi-asserted-by":"crossref","unstructured":"Arikkat, D.R., Abhinav, M., Binu, N., Parvathi, M., Biju, N., Arunima, K.S., Vinod, P., Rafidha Rehiman, K.A., and Conti, M. (2024). IntellBot: Retrieval Augmented LLM Chatbot for Cyber Threat Knowledge Delivery. arXiv.","DOI":"10.1109\/CICN63059.2024.10847404"},{"key":"ref_73","unstructured":"Xu, M., Wang, H., Liu, J., Lin, Y., Liu, C.X.Y., Lim, H.W., and Dong, J.S. (2024). IntelEX: A LLM-driven attack-level threat intelligence extraction framework. arXiv."},{"key":"ref_74","doi-asserted-by":"crossref","first-page":"104213","DOI":"10.1016\/j.cose.2024.104213","article-title":"AECR: Automatic attack technique intelligence extraction based on fine-tuned large language model","volume":"150","author":"Chen","year":"2025","journal-title":"Comput. Secur."},{"key":"ref_75","unstructured":"Paul, S., Alemi, F., and Macwan, R. (2025). LLM-assisted proactive threat intelligence for automated reasoning. arXiv."},{"key":"ref_76","doi-asserted-by":"crossref","unstructured":"Ghosh, S.K., Gjomemo, R., and Venkatakrishnan, V.N. (2024, January 19). Citar: Cyberthreat Intelligence-driven Attack Reconstruction. Proceedings of the Fifteenth ACM Conference on Data and Application Security and Privacy, Pittsburgh, PA, USA.","DOI":"10.1145\/3714393.3726519"},{"key":"ref_77","first-page":"23","article-title":"LLexus: An AI agent system for incident management, SIGOPS Oper","volume":"58","author":"Kumbhare","year":"2024","journal-title":"Syst. Rev."},{"key":"ref_78","unstructured":"Hays, S., and White, J. (2024). Employing LLMs for Incident-Response Planning and Review. arXiv."},{"key":"ref_79","doi-asserted-by":"crossref","unstructured":"Liu, Z. (2025, January 24\u201325). AutoBnB: Multi-Agent Incident Response with Large Language Models. Proceedings of the 2025 13th International Symposium on Digital Forensics and Security (ISDFS), Boston, MA, USA.","DOI":"10.1109\/ISDFS65363.2025.11012055"},{"key":"ref_80","unstructured":"Sun, Y., Luo, Y., Wen, X., Yuan, Y., Nie, X., Zhang, S., Liu, T., and Luo, X. (2025). TrioXpert: An Automated Incident Management Framework for Microservice Systems. arXiv."},{"key":"ref_81","unstructured":"Kramer, D., Rosique, L., Narotam, A., Bursztein, E., Kelley, P.G., Thomas, K., and Woodruff, A. (2025, January 11\u201312). Integrating Large Language Models into Security Incident Response. Proceedings of the Twenty-First Symposium on Usable Privacy and Security (SOUPS 2025), Seattle, WA, USA."},{"key":"ref_82","unstructured":"Singh, R., Chhetri, M.B., Nepal, S., and Paris, C. (2025). ContextBuddy: AI-Enhanced Contextual Insights for Security Alert Investigation. arXiv."},{"key":"ref_83","unstructured":"Jensen, R.I.T., Tawosi, V., and Alamir, S. (2024). Software Vulnerability and Functionality Assessment using LLMs. arXiv."},{"key":"ref_84","unstructured":"Lian, X., Chen, Y., Cheng, R., Huang, J., Thakkar, P., Zhang, M., and Xu, T. (2023). Configuration Validation with Large Language Models. arXiv."},{"key":"ref_85","doi-asserted-by":"crossref","unstructured":"Sheng, Z., Wu, F., Zuo, X., Li, C., Qiao, Y., and Hang, L. (2024). LProtector: An LLM-driven Vulnerability Detection System. arXiv.","DOI":"10.1109\/ICDSCA63855.2024.10859408"},{"key":"ref_86","unstructured":"Xu, M., Fan, J., Huang, X., Zhou, C., Kang, J., Niyato, D., Mao, S., Han, Z., Shen, X., and Lam, K.Y. (2025). Forewarned is Forearmed: A Survey on Large Language Model-based Agents in Autonomous Cyberattacks. arXiv."},{"key":"ref_87","doi-asserted-by":"crossref","unstructured":"Wang, D., Zhou, G., Chen, L., Li, D., and Miao, Y. (2024, January 14\u201318). ProphetFuzz: Fully Automated Prediction and Fuzzing of High-Risk Option Combinations with Only Documentation via Large Language Model. Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, Salt Lake City, UT, USA.","DOI":"10.1145\/3658644.3690231"},{"key":"ref_88","doi-asserted-by":"crossref","first-page":"69175","DOI":"10.1109\/ACCESS.2025.3560911","article-title":"LLM Agentic Workflow for Automated Vulnerability Detection and Remediation in Infrastructure-as-Code","volume":"13","author":"Toprani","year":"2025","journal-title":"IEEE Access"},{"key":"ref_89","doi-asserted-by":"crossref","first-page":"104113","DOI":"10.1016\/j.cose.2024.104113","article-title":"Practically implementing an LLM-supported collaborative vulnerability remediation process: A team-based approach","volume":"148","author":"Wang","year":"2025","journal-title":"Comput. Secur."},{"key":"ref_90","unstructured":"Beck, V., Landauer, M., Wurzenberger, M., Skopik, F., and Rauber, A. (2025). System Log Parsing with Large Language Models: A Review. arXiv."},{"key":"ref_91","doi-asserted-by":"crossref","first-page":"86","DOI":"10.1109\/MC.2025.3544797","article-title":"Agentic Artificial Intelligence for Cyber Threat Management","volume":"58","author":"Kshetri","year":"2025","journal-title":"Computer"},{"key":"ref_92","doi-asserted-by":"crossref","unstructured":"Massengale, S., and Huff, P. (2024, January 17\u201320). Linking Threat Agents to Targeted Organizations: A Pipeline for Enhanced Cybersecurity Risk Metrics. Proceedings of the 2024 4th Intelligent Cybersecurity Conference (ICSC), Valencia, Spain.","DOI":"10.1109\/ICSC63108.2024.10895328"},{"key":"ref_93","unstructured":"Shukla, A., Gandhi, P.A., Elovici, Y., and Shabtai, A. (2025). RuleGenie: SIEM Detection Rule Set Optimization. arXiv."},{"key":"ref_94","unstructured":"Fu, Y., Yuan, X., and Wang, D. (2025). RAS-Eval: A Comprehensive Benchmark for Security Evaluation of LLM Agents in Real-World Environments. arXiv."},{"key":"ref_95","doi-asserted-by":"crossref","unstructured":"Hamadanian, P., Arzani, B., Fouladi, S., Kakarla, S.K.R., Fonseca, R., Billor, D., Cheema, A., Nkposong, E., and Chandra, R. (2023, January 28\u201329). A Holistic View of AI-Driven Network Incident Management. Proceedings of the 22nd ACM Workshop on Hot Topics in Networks (HotNets \u201923), Cambridge, MA, USA.","DOI":"10.1145\/3626111.3628176"},{"key":"ref_96","unstructured":"Bono, J., Grana, J., and Xu, A. (2024). Generative AI and Security Operations Center Productivity: Evidence from Live Operations. arXiv."},{"key":"ref_97","unstructured":"Gandhi, P.A., Shukla, A., Tayouri, D., Ifland, B., Elovici, Y., Puzis, R., and Shabtai, A. (2025). ATAG: AI-Agent Application Threat Assessment with Attack Graphs. arXiv."},{"key":"ref_98","unstructured":"Bountakas, P., Fysarakis, K., Kyriakakis, T., Karafotis, P., Aristeidis, S., Tasouli, M., Alcaraz, C., Alexandris, G., Andronikou, V., and Koutsouri, T. (August, January 30). SYNAPSE\u2014An Integrated Cyber Security Risk & Resilience Management Platform, With Holistic Situational Awareness, Incident Response & Preparedness Capabilities: SYNAPSE. Proceedings of the 19th International Conference on Availability, Reliability and Security, Vienna, Austria."},{"key":"ref_99","unstructured":"Sarkar, A., and Sarkar, S. (2025). Survey of LLM Agent Communication with MCP: A Software Design Pattern Centric Review. arXiv."},{"key":"ref_100","unstructured":"Tseng, P., Yeh, Z., Dai, X., and Liu, P. (2024). Using LLMs to Automate Threat Intelligence Analysis Workflows in Security Operation Centers. arXiv."},{"key":"ref_101","doi-asserted-by":"crossref","first-page":"46","DOI":"10.1109\/MS.2024.3416036","article-title":"Generative AI for Software Security Analysis: Fundamentals, Applications, and Challenges","volume":"41","author":"Ding","year":"2024","journal-title":"IEEE Softw."},{"key":"ref_102","doi-asserted-by":"crossref","unstructured":"Castro, S.R., Campbell, R., Lau, N., Villalobos, O., Duan, J., and Cardenas, A.A. (2025). Large Language Models are Autonomous Cyber Defenders. arXiv.","DOI":"10.1109\/CAI64502.2025.00195"},{"key":"ref_103","doi-asserted-by":"crossref","unstructured":"Saura, P.F., Jayaram, K.R., Isahagian, V., Bernab\u00e9, J.B., and Skarmeta, A. (2025). On Automating Security Policies with Contemporary LLMs. arXiv.","DOI":"10.1109\/SSE67621.2025.00018"},{"key":"ref_104","doi-asserted-by":"crossref","unstructured":"Oesch, S., Chaulagain, A., Weber, B., Dixson, M., Sadovnik, A., Roberson, B., Watson, C., and Austria, P. (2024, January 13). Towards a High Fidelity Training Environment for Autonomous Cyber Defense Agents. Proceedings of the 17th Cyber Security Experimentation and Test Workshop, Philadelphia, PA, USA.","DOI":"10.1145\/3675741.3675752"},{"key":"ref_105","unstructured":"Subramaniam, P., and Krishnan, S. (2024). DePLOI: Applying NL2SQL to Synthesize and Audit Database Access Control. arXiv."},{"key":"ref_106","doi-asserted-by":"crossref","unstructured":"Roy, D., Zhang, X., Bhave, R., Bansal, C., Las-Casas, P., Fonseca, R., and Rajmohan, S. (2024, January 15\u201319). Exploring LLM-based agents for root cause analysis. Proceedings of the ACM International Conference on the Foundations of Software Engineering (FSE Companion), Porto de Galinhas, Brazil.","DOI":"10.1145\/3663529.3663841"},{"key":"ref_107","doi-asserted-by":"crossref","unstructured":"Shah, S.P., and Deshpande, A.V. (2024, January 20\u201321). Addressing Data Poisoning and Model Manipulation Risks using LLM Models in Web Security. Proceedings of the 2024 International Conference on Distributed Systems, Computer Networks and Cybersecurity (ICDSCNC), Bengaluru, India.","DOI":"10.1109\/ICDSCNC62492.2024.10941696"},{"key":"ref_108","doi-asserted-by":"crossref","unstructured":"Kalakoti, R., Vaarandi, R., Bah\u015fi, H., and N\u00f5mm, S. (2025). Evaluating Explainable AI for Deep Learning-Based Network Intrusion Detection System Alert Classification. arXiv.","DOI":"10.5220\/0013180700003899"},{"key":"ref_109","doi-asserted-by":"crossref","first-page":"n71","DOI":"10.1136\/bmj.n71","article-title":"The PRISMA 2020 statement: An updated guideline for reporting systematic reviews","volume":"372","author":"Page","year":"2021","journal-title":"BMJ"}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/95\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,5]],"date-time":"2025-11-05T17:44:32Z","timestamp":1762364672000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/95"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,5]]},"references-count":109,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["jcp5040095"],"URL":"https:\/\/doi.org\/10.3390\/jcp5040095","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,5]]}}}