This demo presents a looping process that autonomously mitigates ongoing attacks by extracting security policies from intrusion detection system alerts and automatically reconfiguring distributed firewalls via a provably correct and optimized approach.
The findings suggest that combining open-source SIEM, workflow automation, and LLM-based reasoning with human supervision offers a practical, low-cost, and reliable approach for strengthening incident response capability in resource-constrained environments.
A closed-loop framework that detects and blocks attacks in software-defined networks without operator involvement is presented, evaluating its performance against this stringent temporal constraint rather than relying exclusively on detection accuracy.
face of these evolving
dangers. It argues that while compliance-based frameworks provide a necessary governance foundation, they are insufficient
without the integration of proactive strategies like Threat Hunting and Threat Intelligence. In this paper, we present the
Integrated Threat Hunting and Security Orchestration, Automation and Response (SOAR) Automation Workflow (THSAW)
highlighting the necessity of shifting from a reactive "alert-driven" posture to a proactive "hunt-driven" methodology to
ensure organizational resilience. Using a design science paradigm, we describe the solution design rationale and artifact
development. The proactive approach can be used to develop the offensive security-aware environment for organizations to
uncover advanced attack mechanisms and test their ability for attack detection. Experimental results demonstrate the
workflow's effectiveness in autonomous threat detection, behavioral analysis, and automated incident response.
Austin Oguejiofor Amaechi, Ekangwo Hernadez Ebolo, Kum Bertrand Kum et al.· International Journal of Inn...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.