🤖 AI Summary
This study addresses the lack of empirical, practitioner-based insights into the applicability and risks of large language models (LLMs) within real-world security operations center (SOC) workflows. Through semi-structured interviews and interactive scenario simulations with 25 SOC practitioners experienced in LLM use, the research systematically identifies six functional categories and 15 concrete use cases for LLMs in cybersecurity operations from a human-centered perspective, while proposing integration design requirements grounded in operational safety. Findings indicate that LLMs are well-suited for low-level, repetitive tasks such as report automation but face limitations in high-impact activities like incident analysis due to insufficient technical depth and contextual awareness. Although practitioners express caution about overreliance, they broadly support the judicious adoption of LLMs within SOC environments.
📝 Abstract
Security Operations Centers (SOCs) process large volumes of security events, requiring analysts to accurately detect and assess ongoing cyberattacks under time pressure. Recent advances in Large Language Models (LLMs) suggest potential benefits for security operations, yet their practical suitability for real-world SOC workflows remains poorly understood. To address this gap, we conducted 25 semi-structured interviews with SOC practitioners who had prior experience with LLMs, complemented by interactive scenarios to anticipate challenges and identify opportunities for the responsible integration of LLM-based tools into SOC workflows. We identified 15 LLM use cases grouped into six functional categories. While LLMs are valued for automating repetitive, low-level tasks such as report automation, practitioners rate high-impact tasks such as incident analysis as not yet feasible, reporting limitations in technical depth, context awareness, and organization-specific knowledge. They locate these limitations less in the models than in the readiness of their SOCs and human factors driving over-reliance. Despite concerns, practitioners express a strong willingness to adopt LLMs, describing competitive pressure that leaves few alternatives. This work contributes an empirical, practitioner-driven analysis of LLM use across SOC roles and organizations and derives concrete design and integration requirements for human-centered, operationally safe LLM-assisted security operations.