A context-aware, AI-driven load balancing framework for incident escalation in SOCs

Yükleniyor...
Küçük Resim

Tarih

2025-08-12

Dergi Başlığı

Dergi ISSN

Cilt Başlığı

Yayıncı

Institute of Electrical and Electronics Engineers Inc.

Erişim Hakkı

info:eu-repo/semantics/closedAccess

Araştırma projeleri

Organizasyon Birimleri

Dergi sayısı

Özet

SOCs face growing challenges in incident management due to increasing alert volumes and the complexity of cyberattacks. Traditional rule-based escalation models often fail to account for the workload of the analyst, the severity of the incident, and the organizational context. This paper proposes a context-aware, AI-driven load balancing framework for intelligent analyst assignment and incident escalation. Our framework leverages large language models (LLMs) with retrievalaugmented generation (RAG) to evaluate incident relevance and historical assignments. A reinforcement learning (RL)-based scheduler continuously optimizes incident-to-analyst assignments based on operational outcomes, enabling the system to adapt to evolving threat landscapes and organizational structures. Planned simulations in realistic SOC environments will compare the model with traditional rule-based models using metrics such as Mean Time to Resolution (MTTR), workload distribution, and escalation accuracy. This work highlights the potential of AIdriven approaches to improve SOC performance and enhance incident response effectiveness.

Açıklama

Anahtar Kelimeler

AI-driven incident escalation, Context-aware assignment, Escalation, Load balancing, Security operation center, Artificial intelligence, Computational methods, Programmable logic controllers, System-on-chip, Context-aware, Cyber-attacks, Incident escalations, Incident management, Rule based, Resource allocation

Kaynak

ISAS 2025 - 9th International Symposium on Innovative Approaches in Smart Technologies, Proceedings

WoS Q Değeri

Scopus Q Değeri

N/A

Cilt

Sayı

Künye

Abuaziz, A. & Çeliktaş, B. (2025). A context-aware, AI-driven load balancing framework for incident escalation in SOCs. papr presented at the ISAS 2025 - 9th International Symposium on Innovative Approaches in Smart Technologies, Proceedings, 1-10. doi:https://doi.org/10.1109/ISAS66241.2025.11101733