Саморегульований центр операцій безпеки на основі федеративного навчання з постквантовими механізмами захищеної агрегації
Abstract
Objective. The objective of the research is to develop an architecture for a self-regulating Security Operations Center (SOC) that ensures autonomous adaptation of agents to new threats by combining federated learning with post-quantum secure model aggregation mechanisms based on lattice cryptography, while simultaneously maintaining the confidentiality of local data and resilience to potential attacks from quantum computing resources. Methodology. The research methodology is based on combining federated learning, post-quantum secure aggregation mechanisms, and an agent-based model of adaptive response to create a self-regulating SOC. The architecture is evaluated through the interaction of three key components: local agents, a post-quantum protected aggregator, and a self-regulation module with the formalization of their mathematical and operational characteristics. The integration of these subsystems allows for the investigation of the level of autonomy, resilience to quantum attacks, and effectiveness in detecting and responding to cyber threats in a decentralized environment. Results. Experimental results on CICIDS2017 and UNSW-NB15 showed that the PQ-FedAvg (Lattice) model maintains high classification accuracy and minimizes aggregation latency, while ensuring a 40–45% reduction in detection and response time compared to traditional centralized SOCs. The agent-oriented self-learning model provides autonomous updating of security policies, reduces operator dependence, and increases system stability in real-time. The developed architecture demonstrates high applicability for decentralized enterprise environments, cloud platforms, and critical infrastructure systems, including Zero Trust SOCs and AI-driven Security Operations. Scientific Novelty. The scientific novelty lies in the substantiation and development of an integrated approach that, for the first time, combines federated learning, post-quantum lattice cryptography, and agent-oriented adaptive management models to create a self-regulating SOC. The proposed architecture eliminates the key limitations of traditional centralized cybersecurity systems by ensuring agent autonomy, telemetry confidentiality, and resilience to quantum attacks during the model aggregation stage. This synergistic model forms a new paradigm for building decentralized SOCs capable of continuous self-adaptation and effective real-time response to evolutionary cyber threats. Practical Significance. The practical significance of the work lies in the fact that the proposed architecture of a self-regulating SOC can be directly implemented in corporate, cloud, and critical infrastructures, ensuring secure collaborative learning without disclosing telemetry and with resilience to quantum attacks. Experimental results on CICIDS2017 and UNSW-NB15 demonstrate that the integration of federated learning with post-quantum secure aggregation mechanisms provides competitive anomaly detection accuracy, as well as a significant reduction in the mean time to detect and respond to incidents. The results obtained confirm the innovativeness of the developed approach for practical application in next-generation SOCs, which are distinguished by high adaptability, autonomy, and cryptographic resilience.