LATIDIA · Ciberseguridad
De fallas de investigación a agentes de SOC confiables: comprensión y mejora del triaje de alertas basado en LLM
arXiv: 2610.10608v1Tipo de anuncio: nuevo Resumen: Los centros de operaciones de seguridad (SOC) deben clasificar grandes volúmenes de alertas, la mayoría de las cuales son benignas, mientras que los ataques perdidos pueden permanecer sin investigar. Herramienta que utiliza un lenguaje grande
WhatsApp ↗Telegram ↗
La noticia
arXiv:2610.10608v1 Announce Type: new Abstract: Security operations centers (SOCs) must triage large volumes of alerts, most of which are benign, while missed attacks can remain uninvestigated. Tool-using large language model (LLM) agents can retrieve evidence during triage, but it remains unclear how reasoning strategies determine what to gather and when an investigation is sufficient to close an alert. We study five representative approaches spanning single-pass tool use, iterative retrieval, sampled investigations, self-review, and explicit verification. To support this study, we build ALERT-BENCH, an interactive benchmark that replays enterprise telemetry through a live SIEM and requires each system to retrieve evidence. Across 1,247 alerts from a multi-stage attack scenario, every approach