AI-Augmented Network-Forensics: Leveraging LLMs for Real-Time Threat Detection and Automated Response in Enterprise Environments
Abstract
In modern enterprise networks, complicated rule-based signatures, fragmented alerts, encrypted traffic, and analyst workloads are delaying the ability to recognize and contain incidents, as the need grows for faster correlation of heterogeneous telemetry. This study evaluates an LLM-augmented network-forensics architecture for threat detection, evidence interpretation, and controlled automated response, while retaining deterministic security controls. The 30-day controlled digital-twin experiment in the medium-sized hybrid enterprise resulted in about 18.6 million security events. The events were correlated into 1,200 incident windows: 480 malicious and 720 benign. Precision, F1-score, Recall, FPR, ROC-AUC, investigation latency, and response accuracy were used to compare the proposed hybrid system with XGBoost, SIEM Rules, and a transformer-based anomaly detection architecture. In the controlled digital-twin evaluation, the LLM-augmented hybrid system achieved an F1 score of 94.2%, a false-positive rate of 3.1%, a mean detection time of 2.6 minutes, a mean response time of 13.4 minutes, and a response-recommendation accuracy of 92.1%. Through retrieval-augmented generation, either with or without schema validation, the amount of unsupported claims decreased from 14.6% to 3.8%. Results showed that LLM performance as contextual reasoning, explanation, and orchestration components in guarded workflows was most effective. For high-impact actions impacting critical assets, privileged identities, or production systems, human approval was required. Multi-enterprise validation, adversarial testing, and privacy-preserving model adaptation should be addressed in the future.
Keywords
References
Most read articles by the same author(s)
- Dr. Wei Zhang, Dr. Li Chen, An Intelligent Knowledge-Driven Clinical Decision Support Framework for Predictive Comorbidity Risk Assessment and Healthcare Decision-Making , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 08 (2026): Volume 03 Issue 08
- Kolchin Rustam, Development and Implementation of the Mail Security Guardian (MSG) System for Multi-Layer Proactive Email Protection Against Spam, Phishing and Malware , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 07 (2026): Volume 03 Issue 07
- Myroslav Mishov, Autonomous Threat Remediation in Localized AI Environments: A Review of Security-as-Code Execution Models , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 06 (2026): Volume 03 Issue 06
- Michael Andrew Thornton, Designing and Evaluating Low Latency Web APIs for High Transaction and Industrial Internet Systems: Architectural, Methodological, and Socio Technical Perspectives , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 01 (2026): Volume 03 Issue 01
- Adrian Velasco, Meera Narayan, REVOLUTIONIZING SILICON PHOTONIC DEVICE DESIGN THROUGH DEEP GENERATIVE MODELS: AN INVERSE APPROACH AND EMERGING TRENDS , International Journal of Advanced Artificial Intelligence Research: Vol. 2 No. 06 (2025): Volume 02 Issue 06
- Angelo soriano, Sheila Ann Mercado, The Convergence of AI And UVM: Advanced Methodologies for the Verification of Complex Low-Power Semiconductor Architectures , International Journal of Advanced Artificial Intelligence Research: Vol. 2 No. 11 (2025): Volume 02 Issue 11
- Dr. Eleni Markou, Narrative Intelligence In The Age Of Generative Ai: Integrating Computational Storytelling, Transformer Architectures, Ethical Governance, And Consumer Impact , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 03 (2026): Volume 03 Issue 03
- Nethika Perera, Kavindu Jayasinghe, Dynamic Risk-Based Access Control for Autonomous Agentic AI Systems: Architecture, Policy Enforcement, and Security Evaluation , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 09 (2026): Volume 03 Issue 09
- Takumi Suzuki, Mio Tanaka, Scalability Constraints in AI-Driven Construction Management: Opportunities for Robotics and LLM Integration , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 08 (2026): Volume 03 Issue 08
- Dr. Mei-Ling Zhou, Dr. Haojie Xu, LEARNING RICH FEATURES WITHOUT LABELS: CONTRASTIVE APPROACHES IN MULTIMODAL ARTIFICIAL INTELLIGENCE SYSTEMS , International Journal of Advanced Artificial Intelligence Research: Vol. 2 No. 04 (2025): Volume 02 Issue 04
Similar Articles
- Mr. Raman Kumar, An Analysis of Explainable Artificial Intelligence for Intelligent Cybersecurity Applications , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 08 (2026): Volume 03 Issue 08
- Sri Charan Chowdary Konidina, An Analytical Study of Behavior-Aware Retrieval-Augmented Generation Frameworks in Enterprise Software Ecosystems for Optimizing User Navigation and Decision Support , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 08 (2026): Volume 03 Issue 08
- John M. Davenport, AI-AUGMENTED FRAMEWORKS FOR DATA QUALITY VALIDATION: INTEGRATING RULE-BASED ENGINES, SEMANTIC DEDUPLICATION, AND GOVERNANCE TOOLS FOR ROBUST LARGE-SCALE DATA PIPELINES , International Journal of Advanced Artificial Intelligence Research: Vol. 2 No. 08 (2025): Volume 02 Issue 08
- Sonam Kumari, Enhancing Clinical Decision-Making Using Generative AI-Powered Knowledge Retrieval Systems: A Review of Emerging Approaches and Challenges , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 08 (2026): Volume 03 Issue 08
- Dr. Haruto Nakamura, Dr. Yui Takahashi, A Deep Unsupervised Artificial Intelligence Model for Automated Prostate Cancer Prediction Through Latent Pattern Discovery and Clinical Data Analysis , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 08 (2026): Volume 03 Issue 08
- Dr. Leila K. Moreno, Integrated Real-Time Fraud Detection and Response: A Streaming Analytics Framework for Financial Transaction Security , International Journal of Advanced Artificial Intelligence Research: Vol. 2 No. 11 (2025): Volume 02 Issue 11
- Suprajyotsna Dasari , Automated Testing Techniques for Enterprise Software Systems with GenAI Integration , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 09 (2026): Volume 03 Issue 09
- Dr. Eleni Markou, Narrative Intelligence In The Age Of Generative Ai: Integrating Computational Storytelling, Transformer Architectures, Ethical Governance, And Consumer Impact , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 03 (2026): Volume 03 Issue 03
- Myroslav Mishov, Autonomous Threat Remediation in Localized AI Environments: A Review of Security-as-Code Execution Models , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 06 (2026): Volume 03 Issue 06
- Prof. Michael T. Edwards, ENHANCING AI-CYBERSECURITY EDUCATION: DEVELOPMENT OF AN AI-BASED CYBERHARASSMENT DETECTION LABORATORY EXERCISE , International Journal of Advanced Artificial Intelligence Research: Vol. 2 No. 02 (2025): Volume 02 Issue 02
You may also start an advanced similarity search for this article.