APPLICATION OF LARGE LANGUAGE MODELS FOR AUTOMATED ANALYSIS OF CYBERSECURITY INCIDENTS
Keywords:
large language models; cybersecurity incident analysis; security operations centre; incident response; retrieval-augmented generation; prompt injection; human-in-the-loopAbstract
Security operations centres (SOCs) face a growing volume of alerts, analyst fatigue and a shortage of qualified specialists, which makes the timely and high-quality analysis of cybersecurity incidents increasingly difficult. Large language models (LLMs), owing to their ability to interpret unstructured texts — logs, alerts, threat intelligence reports — are considered in the recent literature as a promising means of automating this analysis. This article systematizes the documented capabilities of LLMs across the phases of the incident response lifecycle defined by NIST, proposes a five-layer reference architecture for the responsible integration of LLMs into incident analysis processes (data ingestion, knowledge and retrieval, model and orchestration, assurance, audit and compliance), and constructs a structured map of the principal risks of such integration — hallucinations, prompt injection, leakage of sensitive data, adversarial evasion, over-reliance and integration with legacy infrastructure — together with mitigation measures grounded in current guidance. The conclusion is substantiated that, at the present level of technology, LLMs should augment rather than replace the analyst, with mandatory human approval of consequential response actions. The results are oriented towards SOCs of organizations and universities, including in the context of the implementation of the cybersecurity strategy of the Republic of Uzbekistan for 2026–2030.