Score
Designs, builds, and operates staffing, scheduling, and operational processes and tools that ensure continuous incident monitoring, escalation, and response, including on-call rotations, follow-the-sun scheduling, handoffs, and readiness checks. Creates and maintains procedures, runbooks, communication and leadership practices, and metrics to coordinate on-call operations, support, and engineering response.
This study addresses occupational burnout among Security Operations Center (SOC) practitioners, often stemming from misalignment between job demands and individual capabilities. Drawing on flow theory, the authors conduct an inductive content analysis of 106 global SOC job postings to systematically map the prevalence of certifications (e.g., CISSP), technical skills (e.g., Python, Splunk), and soft skills—particularly communication skills, mentioned in 50.9% of listings. The research reveals, for the first time, a structured pattern in the skill and certification requirements of SOC roles. These findings provide empirical grounding for achieving challenge–skill balance, refining recruitment practices, and guiding professional development. Furthermore, the study advances the discourse on flow-aligned person–job fit and sets the stage for future investigations into the impact of artificial intelligence on SOC workforce dynamics.
This study addresses the lack of effective handover guidance in current cybersecurity incident response teams, which undermines response continuity and operational efficiency. Through a comprehensive literature review and semi-structured interviews with practitioners, this work proposes the first systematic framework for cybersecurity handover protocols. The framework innovatively incorporates post-incident debriefing and service status modules, while integrating critical elements such as endorsement cues, procedural evolution, and individual differences. Iteratively refined through multiple rounds of feedback, the resulting handover guidelines have garnered strong endorsement from frontline responders, who also contributed supplementary recommendations. This research establishes a practical foundation for enhancing handover quality and improving team coordination in cybersecurity operations.
This study addresses a critical training crisis in 9-1-1 emergency call centers, where staffing shortages exceed 25% and conventional training demands up to 720 hours per operator while lacking scalability. In collaboration with Nashville’s Emergency Communications Department, the authors deployed—within an active operational environment—the first large-scale, generative AI–driven interactive training system for emergency dispatchers. Over six months, the system engaged 190 operators across 1,120 training sessions and 98,429 user interactions. The research identifies four human-centered AI design and governance practices tailored to real-world constraints, uncovers systemic challenges invisible in simulated settings, and demonstrates the feasibility of generative AI for high-stakes public safety training. The findings yield actionable design principles and implementation guidelines that are readily transferable to comparable domains.
This work addresses the limitations of traditional expert-manual-based cybersecurity response methods, which struggle to adapt to dynamic attack scenarios and evolving recovery objectives, as well as the instability of existing large-model approaches in long-horizon tasks. The authors propose an end-to-end agent planning framework that innovatively models event states using a graph structure (Graph-as-State), incorporates a phase-aware agent routing mechanism, and establishes a verifiable experience reuse loop to guide action selection and state updates. The system integrates multi-agent large language models with experience retrieval augmentation and execution feedback verification, enabling dynamic, stable, and evolvable response planning within a Docker-based network range simulation environment. Experimental results demonstrate that the proposed method achieves a normalized defense score of 0.94 across 100 simulated scenarios, representing a 9.5% improvement over the strongest baseline.
This study addresses the trade-off between cost and service quality in multichannel customer service by modeling the entire service process as a gated system. It jointly optimizes decisions across three levels: strategic (channel deployment), tactical (staffing and AI allocation), and operational (real-time scheduling). Leveraging operations research, dynamic modeling, and numerical simulation, the work derives a structured optimal request-handling policy and uncovers a counterintuitive insight: judicious deployment of AI chatbots not only enhances service efficiency but also significantly improves service quality, thereby achieving simultaneous optimization of cost and customer experience.
This work addresses inefficiencies in Network Operations Centers (NOCs)—including fragmented information retrieval, verbose ticketing, and loss of contextual continuity during handoffs—stemming from data silos. To mitigate these challenges, the authors propose ORBIT, an intelligent agent system integrated into the ServiceNow platform. ORBIT employs a modular, layered architecture that encapsulates task logic into versioned, testable “skills,” ensuring reliable and scalable operation within constrained behavioral boundaries. Its core components comprise a centralized reasoning engine, an MCP protocol interface to ESnet, a semantic search layer, an operational chat interface, and a LiteLLM model gateway. Evaluated on six initial tasks and rapidly adapted to two new ones, ORBIT significantly reduces operational steps, eliminates known error patterns, and sees broad adoption of its reusable components, thereby lowering cognitive load and accelerating incident response.
This study addresses the challenge of LLM agents adapting to dynamic organizational standards during alert triage in Security Operations Centers. To this end, it proposes a feedback-driven continuous evolution framework grounded in structured skill representations. The core innovation lies in enforcing a hard constraint of 1.0 recall to maximize the automated closure of false positives, while identifying judgment blind spots by integrating alert distributions with model error boundaries. Experimental evaluations across four real-world industrial scenarios demonstrate that the proposed method achieves full recall on all evolution sets, with three scenarios maintaining perfect recall throughout future testing windows. These results indicate that the framework significantly outperforms baseline approaches, offering a robust and adaptive solution for automated security alert triage under evolving operational criteria.
本文设计了一个基于规则引擎和本地大型语言模型的教育信息系统警报后事件协调与响应子系统,通过实验验证了其功能正确性和可控性。
This work addresses the challenge of prioritizing massive volumes of security events in large-scale Security Operations Centers (SOCs), where traditional time-based or coarse-grained severity-based ranking fails to accurately reflect true analyst priorities, thereby increasing cognitive load. The authors propose Adaptive Incident Prioritization (AIP), a novel algorithm that adapts BM25-style ranking to the query-free, multi-tenant SOC queue setting. AIP leverages normalized representations of security components and integrates saturated local frequency, cross-tenant global rarity, bounded domain-specific priors, and component-level interpretability to enable near real-time, low-latency re-ranking. The study introduces the first publicly available dataset with real-world incident priority labels and demonstrates 92.8% Precision@10 across evaluations involving over a thousand customers. Deployment results show significant improvements in analyst interaction efficiency compared to baseline methods, with a 5.8% increase in alert detail views and a 17.5% rise in incident reviews.
This study addresses fatigue and safety risks faced by freight rail engineers due to on-call scheduling and uncertain transportation demand. To enhance schedule flexibility and predictability of rest periods while complying with Hours of Service regulations, the authors propose a call-window-based crew assignment mechanism as an alternative to traditional fixed assignments. They formalize this scheduling problem for the first time and develop a set-covering optimization model alongside a constructive heuristic algorithm, incorporating constraints such as deadhead trips, delay tolerance, and crew availability limits. Computational experiments on two- and three-city instances demonstrate that the optimization model achieves demand coverage rates of 94.89% and 91.09%, respectively—significantly outperforming the heuristic—while also yielding superior rest allocations and lower delays.