Playbook-Guided Executable SOC Automation for Privacy-Preserving Response in Distributed Networked Systems
Abstract
INTRODUCTION: Distributed networks require security operations center (SOC) automation that connects data security monitoring, privacy-aware evidence handling, controlled execution, and measurable evidence. Static playbooks cannot fully handle ambiguous cross-domain incident context.
Objectives
This paper presents an executable multi-agent framework for data security monitoring and response in distributed networks.
Methods
LLM-based roles generate event analysis, tasks, actions, commands, execution records, and summaries. Security orchestration, automation, and response (SOAR) playbooks and a virtual security capability layer provide controlled execution and repeatable evaluation.
Results
On 83 labeled incidents, the framework achieved 0.9684 precision, 0.4742 recall, 0.6367 F1-score, and 76.45 s average handling time for tool-call evaluation.
Conclusion
The framework makes distributed data-security response auditable and quantitatively evaluable. The main improvement direction is stronger planning verification for complex multi-step incidents.