Jul 2026· 2026 7th International Conference on Smart Systems and Inventive Technology (ICSSIT)· pp. 1524-1530· 0 citations· 15 references
Abstract
In light of the increased cyber-attacks and complex nature of IT infrastructure today, traditional monitoring systems for security have been identified to be slow and ineffective. Security Operation Centers (SOCs) still employ manual log analysis which causes delays in detecting threats and responding to them. In order to solve this problem, this paper presents the design of an Autonomous Incident Triage and Response Agent (AITRA). The proposed system is an easy and affordable solution which will be based on the idea behind SOAR technology. The proposed system seeks to automate the whole incident management lifecycle by carrying out tasks including log ingestion, event analysis, incident detection, and recommendation of responses. It receives data from sources such as system logs and authentication logs then analyzes them using rule-based analysis methods in order to detect suspicious activities such as failed login attempts, invalid access to the system by users, and escalation of privileges. A decision tree classifier machine learning algorithm is applied in order to categorize behaviors exhibited by the system and enhance detection capabilities. Detected incidents are recorded in a MariaDB database. Some of these responses include blocking IP addresses, suspending suspicious accounts, and informing the administrator. A user-friendly web-based interface that uses React and Flask technologies to help the user perform log upload, incident analysis, and receive appropriate responses is made possible by this software. Experimental evaluation results indicate that this new system makes more efficient use of time and effort than traditional methods and therefore provides better results. This is an implementation of a SOAR system in its miniature version which has the potential for further developments in future.
An AI-driven Security Orchestration, Automation and Response (SOAR) platform that involves: secure authentication, central monitoring, machine learning-based anomaly detection, Groq AI-driven incident analysis, threat intelligence enhancement, n8n workflow automation, AI chatbot, and automatic reporting is focused on.
Bhumika A R, Jhanavi H N, Prof. Thejaswini M N· International Journal of Adv...· 0 citations
Security Operations Centers (SOCs) increasingly rely on Security Orchestration, Automation, and Response (SOAR) platforms to manage high-volume alerts, enrich telemetry, execute playbooks, and shorten incident-response cycles. However, many deployed SOAR systems remain rule dominated: actions are triggered by static if-then playbooks, threshold scores, and analyst-defined routing logic. Such deterministic automation is auditable and operationally useful for known, repetitive events, but it becomes brittle when adversary behavior shifts, telemetry quality varies, alert streams are noisy, assets have unequal business criticality, and compliance constraints differ across response contexts. This paper proposes an Intelligent Security Operations Automation Algorithm (ISOAA) for AI-enabled SOAR. The algorithm integrates probabilistic alert risk scoring, event-graph representation, constrained response optimization, governance-risk-compliance (GRC) gating, human-in-the-loop validation, and feedback-based policy improvement. The mathematical core models each alert as a feature-bearing security object, transforms heterogeneous telemetry into a state representation, estimates actionable incident probability, and selects response actions by maximizing expected security utility subject to operational cost, false-positive loss, and compliance penalty. A rule-based SOAR baseline, an ML-assisted triage baseline, and a reinforcement-learning cyber-response baseline are used for comparative analysis. Controlled benchmark results indicate that ISOAA achieves lower mean time to detect, lower mean time to respond, higher containment success, improved precision and recall, reduced false-positive automation, and lower compliance-breach rate than rule-based SOAR. The paper contributes a defensible mathematical architecture for intelligent SOC automation and offers practical deployment recommendations for risk-aware, auditable, and GRC-constrained response orchestration.
Ikenna Mbuko, O. Ijiga, L. Enyejo· International Journal of Eng...· 0 citations
The findings suggest that combining open-source SIEM, workflow automation, and LLM-based reasoning with human supervision offers a practical, low-cost, and reliable approach for strengthening incident response capability in resource-constrained environments.
Experimental evaluation demonstrates up to 95% detection accuracy, a 50% reduction in response latency, and scalability to over 100,000 IoT devices without performance degradation, highlighting the suitability of SC-ARS for deployment in smart cities, industrial IoT, and decentralized critical infrastructures where trust, transparency, and real-time responsiveness are essential.
S. Bassey, B. Stephen, Emediong Bassey Obot et al.· E3S Web of Conferences· 0 citations
: This paper presents a closed-loop self-healing architecture for incident management in Infrastructure-as-Code (IaC) environments, structured as an instantiation of the MAPE–K (Monitor–Analyze–Plan–Execute over Knowledge) pattern. The main contribution is an architecture that connects runtime monitoring, time-series-based anomaly analysis, remediation planning, and IaC-based execution into a codified and auditable feedback loop. We first analyze a catalog of 20 IaC incident-management rules to identify which incident types exhibit temporal behavior and may therefore benefit from time-series-based analysis. We then instantiate the architecture for one controlled SSH-related anomaly scenario, where Moving Average (MA) and ARIMA are used as lightweight statistical detectors and Ansible playbooks are used to trigger a temporary ban/unban remediation action. The results provide proof-of-concept evidence that time-series anomaly signals can be linked to codified IaC remediation within a complete detection-to-remediation loop.
Ali Ghamgosar Kisomi, Florian Hofer, Nabil El Ioini et al.· International Conference on...· 0 citations
The rapid growth of Internet of Things (IoT) deployments has resulted in massive streams of heterogeneous sensor data, making dependable anomaly detection indispensable for supporting the security, operational efficiency, and reliability of a system. Nonetheless, several current approaches depend on one detection technique, limiting robustness when handling nosisy and partially dealing labeled IoT data. This paper produces a software-defined IoT analytics platform to incorporate several anomaly detection techniques through a containerized ELK (Elasticsearch Logstash-Kibana) architecture deployed based on the use of Docker. The platform consolidates the use of supervised machine learning, fuzzy logic inference, unsupervised isolation Forest approach, and rule-based detection to assess real-world sensor data and improve the robustness of anomaly detection performance. Experiments were carried out on a dataset that contains 9,606 IoT sensor records, where the most effective performance was achieved by the supervised learning model with 98.14% precision, 96.66% accuracy, an F1-score of 93.54%, and 89.35% recall. On the other hand, 87.70% accuracy was achieved by the fuzzy logic model with a 75.71% F1-score. Additionally, 426 high-confidence anomalies were determined by the cross-method intersection analysis by revealing the effectiveness of integrating heterogeneous detection approaches. The experimental results demonstrate that the produced platform strengthens the robustness of anomaly detection while preserving cost efficiency, scalability, and low deployment complexity and ensuring its appropriateness for industrial and research IoT monitoring applications.
Unknown authors· Journal of Sustainable Smart...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.