ChatSOC: A Large Language Model Powered Autonomous Agent for Security Operations Center
J. Wang*,
C. Zhou,
Y. Yi,
Q. Sun,
T. Yan and
F. Qi*: corresponding author
Published on:
October 20, 2025
Abstract
To defend against numerous cyberattacks, the Security Operations Center at the Institute of High Energy Physics (IHEP SOC) was established in 2021. IHEP SOC implemented a standardized procedure for invoking several security tools to execute automated response tasks. This standardized process utilizes a predefined set of tools to ensure that the IHEP SOC maintains minute-level response times, with a remarkably low false block rate of one in ten thousand. However, the fixed process of tool invoking is often challenging to update and manage, and it typically addresses isolated security operational tasks. To address this issue, this paper introduces ChatSOC, an autonomous agent for network security operations empowered by an LLM, capable of completing various operational tasks: identification, protection, detection, and response. ChatSOC streamlines these operations by dynamically planning and executing tasks without relying on fixed processes for tool invocation. Through its deployment at the Institute of High Energy Physics (IHEP), ChatSOC has proven highly effective, enhancing security operations by automatically planning and invoking different tools.
DOI: https://doi.org/10.22323/1.488.0009
How to cite
Metadata are provided both in
article format (very
similar to INSPIRE)
as this helps creating very compact bibliographies which
can be beneficial to authors and readers, and in
proceeding format which
is more detailed and complete.