Skip to content
Preprint

Beyond the Hype: Evaluating LLM Integration and Practical Limitations in Security Operation Centers

Aug 2026 · 0 citations · 43 references
Computer Science

TL;DR

A maturity rubric is introduced to characterize readiness for LLM integration and a research agenda emphasizing auditability and transparent explanation mechanisms to support safer adoption in SOC workflows is outlined.

Abstract

Large Language Models (LLMs) are increasingly being explored within Security Operation Centers (SOCs) to support text-heavy analytical work such as alert contextualization, incident summarization, and drafting investigative artifacts. Despite this interest, practitioners describe critical operational concerns, most notably hallucinations (plausible but incorrect outputs), opaque reasoning, and the verification effort required to safely use model-generated content in security workflows. In this paper, we present findings from semi-structured interviews with 20 SOC practitioners spanning frontline analysts, SOC managers, and tool developers. Participants report perceived time savings for low-stakes tasks that are quickly verifiable (e.g., summarizing logs or drafting initial investigative leads), but they consistently frame LLM outputs as preliminary drafts and suggestions rather than decision-grade conclusions. Participants also describe limited trust in LLMs for high-stakes security decisions due to unreliable outputs and unclear model reasoning, and they report relying primarily on ad-hoc verification norms and continuous human oversight rather than standardized mitigation procedures. Based on these interview-grounded accounts, we introduce a maturity rubric to characterize readiness for LLM integration and outline a research agenda emphasizing auditability and transparent explanation mechanisms to support safer adoption in SOC workflows.

View source

Similar papers

Preprint Aug 2026

From Chasing Ghosts to Missed Attacks: Perspectives and Perceptions of SOC Practitioners on LLM Integration, Risks, and Readiness

This work contributes an empirical, practitioner-driven analysis of LLM use across SOC roles and organizations and derives concrete design and integration requirements for human-centered, operationally safe LLM-assisted security operations.

Jonas Thurner, Nadine Jost, Stefan Albert Horstmann et al. · 0 citations
Book Open access Aug 2026

OmniVul: A Holistic, Multi-Turn Conversational Benchmark for LLM-Based Vulnerability Assessment

With more than 20,000 Common Vulnerabilities and Exposures (CVEs) reported annually, software vulnerabilities represent a critical cybersecurity challenge. This volume has intensified the demand for automated detection and analysis, motivating the integration of large language models (LLMs) for such tasks. However, exi...

Vishnu Teja Kandalam, Viet Duong, Xiaochang Li et al. · 0 citations
Preprint Aug 2026

LMSM: LLM Security Framework Inspired by Linux Security Modules

This work presents Language Model Security Modules (LMSM), a security framework that adapts the separation behind Linux Security Modules (LSM) to LLM serving and gives advances in interpretability and model-internal analysis a common path to runtime enforcement.

XiuYu Zhang, Bo-Nan Ruan, Jun-Feng Fang et al. · 0 citations
Jul 2026

Poster: Rethinking Security in LLM Code Generation through Real-World Risk Scenarios

A developer-centric perspective is adopted and three representative risk scenarios that commonly lead to security vulnerabilities in LLM-generated code are identified: Ambiguous Requirements, Under-Specified Operational Context, and Security--Functionality Conflict are identified.

Lixun Ma, Ruo-Long Ma, Bei Wang et al. · 0 citations
Open access Jul 2026

Integrating generative AI into forensic workflows: A case study from the Netherlands Forensic Institute.

Large Language Models (LLMs) such as ChatGPT promise efficiency gains in routine text-based work, but their use in forensic settings raises challenges for confidentiality, governance, and forensic validation. Prior studies have evaluated LLMs on single tasks within single forensic disciplines, leaving open the question...

T. Meconi, Hans Henseler · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.