Volume 488 - International Symposium on Grids & Clouds (ISGC2025) (ISGC2025) - Network, Security, Infrastructure & Operations
ChatSOC: A Large Language Model Powered Autonomous Agent for Security Operations Center
J. Wang*, C. Zhou, Y. Yi, Q. Sun, T. Yan and F. Qi
*: corresponding author
Full text: pdf
Published on: October 20, 2025
Abstract
To defend against numerous cyberattacks, the Security Operations Center at the Institute of High Energy Physics (IHEP SOC) was established in 2021. IHEP SOC implemented a standardized procedure for invoking several security tools to execute automated response tasks. This standardized process utilizes a predefined set of tools to ensure that the IHEP SOC maintains minute-level response times, with a remarkably low false block rate of one in ten thousand. However, the fixed process of tool invoking is often challenging to update and manage, and it typically addresses isolated security operational tasks. To address this issue, this paper introduces ChatSOC, an autonomous agent for network security operations empowered by an LLM, capable of completing various operational tasks: identification, protection, detection, and response. ChatSOC streamlines these operations by dynamically planning and executing tasks without relying on fixed processes for tool invocation. Through its deployment at the Institute of High Energy Physics (IHEP), ChatSOC has proven highly effective, enhancing security operations by automatically planning and invoking different tools.
DOI: https://doi.org/10.22323/1.488.0009
How to cite

Metadata are provided both in article format (very similar to INSPIRE) as this helps creating very compact bibliographies which can be beneficial to authors and readers, and in proceeding format which is more detailed and complete.

Open Access
Creative Commons LicenseCopyright owned by the author(s) under the term of the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.