从追逐幽灵到被遗漏的攻击:安全运营中心从业者对大型语言模型(LLM)整合、风险及准备情况的看法与认知
From Chasing Ghosts to Missed Attacks: Perspectives and Perceptions of SOC Practitioners on LLM Integration, Risks, and Readiness
浏览论文内容
中文总结 AI 辅助
本研究通过对25名有LLM使用经验的SOC从业者访谈,分析LLM在SOC的应用情况,明确其优势与局限,推导LLM辅助安全运营的设计与整合要求。
中文摘要 AI 辅助
安全运营中心(SOC)需处理海量安全事件,要求分析师在时间压力下准确检测和评估正在发生的网络攻击。大型语言模型(LLM)的最新进展为安全运营带来潜在益处,但其对真实世界SOC工作流程的实际适用性仍鲜为人知。为填补这一空白,我们对25名有LLM使用经验的SOC从业者开展半结构化访谈,并辅以互动场景,以预判挑战、识别将基于LLM的工具负责任整合进SOC工作流程的机遇。我们确定了15个LLM用例,归为6个功能类别。尽管LLM因能自动化报告生成等重复性低层级任务而受重视,但从业者认为事件分析等高影响力任务目前尚不具备可行性,报告其存在技术深度、上下文感知及组织特定知识方面的局限。他们将这些局限归因于SOC的准备程度及导致过度依赖的人为因素,而非模型本身。尽管存在担忧,从业者仍表现出强烈的LLM采用意愿,称竞争压力使其几乎别无选择。本研究提供了由从业者驱动的、关于SOC角色与组织中LLM使用的实证分析,并推导了以人为本、操作安全的LLM辅助安全运营的具体设计与整合要求。
英文摘要
Security Operations Centers (SOCs) process large volumes of security events, requiring analysts to accurately detect and assess ongoing cyberattacks under time pressure. Recent advances in Large Language Models (LLMs) suggest potential benefits for security operations, yet their practical suitability for real-world SOC workflows remains poorly understood. To address this gap, we conducted 25 semi-structured interviews with SOC practitioners who had prior experience with LLMs, complemented by interactive scenarios to anticipate challenges and identify opportunities for the responsible integration of LLM-based tools into SOC workflows. We identified 15 LLM use cases grouped into six functional categories. While LLMs are valued for automating repetitive, low-level tasks such as report automation, practitioners rate high-impact tasks such as incident analysis as not yet feasible, reporting limitations in technical depth, context awareness, and organization-specific knowledge. They locate these limitations less in the models than in the readiness of their SOCs and human factors driving over-reliance. Despite concerns, practitioners express a strong willingness to adopt LLMs, describing competitive pressure that leaves few alternatives. This work contributes an empirical, practitioner-driven analysis of LLM use across SOC roles and organizations and derives concrete design and integration requirements for human-centered, operationally safe LLM-assisted security operations.
发表机构
- Ruhr University Bochum(波鸿鲁尔大学)
- University of Cologne(科隆大学)
- Fraunhofer SIT(弗劳恩霍夫信息技术与系统研究所)
- ICSI, UC Berkeley(加州大学伯克利分校国际计算机科学研究所)
机构由 AI 辅助整理,请以论文原文为准。