Open Access

AI-Augmented Network-Forensics: Leveraging LLMs for Real-Time Threat Detection and Automated Response in Enterprise Environments

4 Senior Software Engineer Santa Clara, CA 95051, USA

Abstract

In modern enterprise networks, complicated rule-based signatures, fragmented alerts, encrypted traffic, and analyst workloads are delaying the ability to recognize and contain incidents, as the need grows for faster correlation of heterogeneous telemetry. This study evaluates an LLM-augmented network-forensics architecture for threat detection, evidence interpretation, and controlled automated response, while retaining deterministic security controls. The 30-day controlled digital-twin experiment in the medium-sized hybrid enterprise resulted in about 18.6 million security events. The events were correlated into 1,200 incident windows: 480 malicious and 720 benign. Precision, F1-score, Recall, FPR, ROC-AUC, investigation latency, and response accuracy were used to compare the proposed hybrid system with XGBoost, SIEM Rules, and a transformer-based anomaly detection architecture. In the controlled digital-twin evaluation, the LLM-augmented hybrid system achieved an F1 score of 94.2%, a false-positive rate of 3.1%, a mean detection time of 2.6 minutes, a mean response time of 13.4 minutes, and a response-recommendation accuracy of 92.1%. Through retrieval-augmented generation, either with or without schema validation, the amount of unsupported claims decreased from 14.6% to 3.8%. Results showed that LLM performance as contextual reasoning, explanation, and orchestration components in guarded workflows was most effective. For high-impact actions impacting critical assets, privileged identities, or production systems, human approval was required. Multi-enterprise validation, adversarial testing, and privacy-preserving model adaptation should be addressed in the future.

Keywords

References

E. Chuah, H. Kalutarage, K. Tasdemir, A. Abrham, and C. Maple, “A systematic literature review of log-correlation tools for cyberattack detection and prediction in large networks,” Journal of Information Security and Applications, vol. 92, Art. no. 104096, 2025. https://www.researchgate.net/profile/Carsten-Maple-2/publication/391628157
Verizon Business, 2025 Data Breach Investigations Report. Verizon, 2025. https://www.verizon.com/business/resources/reports/dbir/
R. Doriguzzi-Corin, L. A. D. Knob, L. Mendozzi, D. Siracusa, and M. Savi, “Introducing packet-level analysis in programmable data planes to advance network intrusion detection,” Computer Networks, vol. 239, Art. no. 110162, 2024. https://arxiv.org/pdf/2307.05936
T. T. Bukhari, O. Oladimeji, E. D. Etim, and J. O. Ajayi, “Systematic review of SIEM integration for threat detection and log correlation in AWS-based infrastructure,” Shodhshauryam, International Scientific Refereed Research Journal, vol. 6, no. 5, pp. 479–512, 2023. https://shisrrj.com/paper/SHISRRJ236539.pdf
G. Skjøtskift, M. Eian, and S. Bromander, “Automated ATT&CK technique chaining,” Digital Threats: Research and Practice, vol. 6, no. 1, pp. 1–11, 2025. https://scholar.google.com/scholar?output=instlink&q=info:0cwpqXmRTkEJ:scholar.googl e.com/&hl=en&as_sdt=0,5&scillfp=5907907535666894531&oi=lle
P. K. R. Prakashkumar, “Secure bank integration framework for Oracle ERP Fusion: Enhancing payment disbursement, Auto Lockbox, and bank account reconciliation,” European Economic Letters, vol. 15, no. 4, pp. 2505–2517, 2025. https://www.eelet.org.uk/index.php/journal/article/view/4082
Y. Alash, R. Altuma, and L. Al-Jobouri, “Implementing packet-level Internet traffic classification using XGBoost in software-defined networking,” International Journal of Intelligent Engineering&Systems, vol. 18, no. 9,2025. https://www.researchgate.net/profile/Yousif-Alash/publication/396176583
A. Pekar, R. Plny, and K. Hynek, “Tutorial on flow-based network traffic classification using machine learning,”arXiv preprint arXiv:2601.04089, 2026. https://arxiv.org/pdf/2601.04089
Y. Al-E’mari, Y. Sanjalawe, and S. Fraihat, “A novel quantum epigenetic algorithm for adaptive cybersecurity threat detection,” AI, vol. 6, no. 8, Art. no. 165, 2025. https://www.mdpi.com/2673-2688/6/8/165
K. S. Chadha, P. R. Vennamaneni, and J. Sardana, “Leveraging advanced analytics and AI-powered solutions for transforming healthcare and retail e-commerce: Enhancing data security, personalization, and compliance,” International Journal of Applied Mathematics, vol. 38, no. 9s, pp.1310–1334, 2025. https://ijamjournal.org/ijam/publication/index.php/ijam/article/download/862/797
H. Alqahtani and G. Kumar, “Large language models for cybersecurity intelligence: A systematic review of emerging threats, defensive capabilities, and security evaluation frameworks,”Computers, Materials & Continua,vol. 87,no.3,2026. https://openurl.ebsco.com/contentitem/gcd:192992781
[A. Ubale, “Beyond telematics: Leveraging generative AI for synthetic accident reconstruction and liability attribution in autonomous vehicle claims,” International Journal of AI, BigData, Computational and Management Studies, vol. 4, no. 4, pp. 119–124, 2023. https://ijaibdcms.org/index.php/ijaibdcms/article/download/356/352
X. Cadet et al., “Retrieval-augmented LLMs for security incident analysis,” in Proc. ACM Conf. AI and Agentic Systems, May 2026, pp. 103–123. https://dl.acm.org/doi/pdf/10.1145/3786335.3813136
V. A. Memos, C. L. Stergiou, A. I. Bermperis, A. P. Plageras, and K. E. Psannis, “A novel architecture for mitigating botnet threats in AI-powered IoT environments,” Sensors, vol. 26, no. 2, Art. no. 572, 2026. https://www.mdpi.com/1424-8220/26/2/572
S. K. R. Vanama, “Integrating site reliability engineering SRE principles into enterprise architecture for predictive resilience,” International Journal of Emerging Trends in Computer Science and Information Technology, vol. 4, no. 3, pp. 164–170, 2023. https://www.ijetcsit.org/index.php/ijetcsit/article/download/514/462
N. Swaminathan and D. Danks, “Governing ethical gaps in distributed AI development,” Digital Society, vol. 3, no. 1, Art. no. 7, 2024. https://link.springer.com/content/pdf/10.1007/s44206-024-00088-0.pdf
S. K. Vishwakarma, “AI-driven predictive risk modeling for aerospace supply chains,” International Journal of Innovation in Business & Economics and Applied Journal, 2025. https://www.iibajournal.org/index.php/iibeaj/article/view/64
R. Hariharan, “Automated incident response using AI-based decision trees,” Computer Fraud & Security, 2025. https://computerfraudsecurity.com/index.php/journal/article/view/783
G. Nguyen, S. Dlugolinsky, V. Tran, and Á. López García, “Network security AIOps for online stream data monitoring,” Neural Computing and Applications, vol. 36, no. 24, pp. 14925–14949, 2024. https://link.springer.com/content/pdf/10.1007/s00521-024-09863-z.pdf
T. A. Kumari and S. Mishra, “Tachyon: Enhancing stacked models using Bayesian optimization for intrusion detection using different sampling approaches,” Egyptian Informatics Journal, vol. 27, Art. no.100520, 2024.https://www.sciencedirect.com/science/article/pii/S1110866524000835
J. Baek, S. Jeong, M. Kang, J. C. Park, and S. Hwang, “Knowledge-augmented language model verification,” in Proc. 2023 Conf. Empirical Methods in Natural Language Processing, Dec. 2023, pp. 1720–1736. https://aclanthology.org/2023.emnlp-main.107.pdf
P. K. R. Prakashkumar and S. Gondi, “Optimized integration of Oracle ERP Fusion and ADP for payroll processing and automated journal entries,” Advances in Consumer Research, vol. 3, no. 1, pp. 1327–1336, 2026. https://acr-journal.com/article/optimized-integration-of-oracle-erp-fusion-and-adp-for-payroll-processing-and-automated-journal-entries-2541
M. W. Arshad, S. Lodi, D. Q. Liu, U. Adeel, and S. R. Hassan, “Calibration-aware gating for budgeted LLM supervision in graph neural network link prediction,” Discover Computing, vol. 29, no. 1, Art. no. 382, 2026. https://link.springer.com/content/pdf/10.1007/s10791-026-10214-w.pdf
J. Lott, D. McShannon, and N. Dietrich, “A selective deep learning framework for pressure injury staging with calibrated confidence and automated clinical documentation,” Intensive and Critical Care Nursing, vol. 97, Art. no. 104466, 2026. https://www.sciencedirect.com/science/article/pii/S0964339726001345
L. Theodorakopoulos and A. Theodoropoulou, “Auditable LLM autonomy for operational decision-making: Big data evidence and decision traces,” Computers, Materials & Continua, vol. 88, no. 2, 2026. https://openurl.ebsco.com/contentitem/gcd:194646818
Ö. Sen, C. Eze, A. Ulbig, and A. Monti, “On holistic multi-step cyberattack detection via a graph-based correlation approach,” in Proc. 2022 IEEE Int. Conf. Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm), Oct. 2022, pp. 380–386. https://arxiv.org/pdf/2211.10971
S. K. R. Vanama, “AI-augmented CI/CD pipeline optimization for scalable cloud-native deployment,” International Journal of Artificial Intelligence, Data Science, and Machine Learning, vol.5, no. 4, pp.175–187,2024.https://ijaidsml.org/index.php/ijaidsml/article/download/368/338
Ismail et al., “Toward robust security orchestration and automated response in security operations centers with a hyper-automation approach using agentic artificial intelligence,”Information, vol. 16, no. 5, Art. no. 365, 2025. https://www.mdpi.com/2078-2489/16/5/365
N. Kumar, “Edge computing patterns for real-time order flow optimization,” International Journal of Applied Mathematics, vol. 38, no. 12s, 2025.
Y. Song et al., “A multi-source log semantic analysis-based attack investigation approach,”Computers & Security, vol. 150, Art. no. 104303, 2025. https://www.sciencedirect.com/science/article/pii/S0167404824006096
M. Baruwal Chhetri, S. Tariq, R. Singh, F. Jalalvand, C. Paris, and S. Nepal, “Towards human–AI teaming to mitigate alert fatigue in security operations centres,” ACM Transactions on Internet Technology, vol. 24, no. 3, pp. 1–22, 2024.https://scholar.google.com/scholar?output=instlink&q=info:wsfX68Ybs9gJ:scholar.google. com/
Samala, “Automated rollback triggers in Jira: Linking failed deployments to incident management,” ComputerFrau&Security,2025. https://computerfraudsecurity.com/index.php/journal/article/view/787
M. Dubiel, Y. Barghouti, K. Kudryavtseva, and L. A. Leiva, “On-device query intent prediction with lightweight LLMs to support ubiquitous conversations,” Scientific Reports, vol. 14, no. 1, Art. no. 12731, 2024. https://www.nature.com/articles/s41598-024-63380-6.pdf
P. Kumar, S. K. Sharma, and V. Dutot, “Artificial intelligence-enabled CRM capability in healthcare: The impact on service innovation,” International Journal of Information Management, vol. 69, Art. no. 102598,2023.https://www.sciencedirect.com/science/article/pii/S0268401222001323
S. Rangu, “Analyzing the impact of AI-powered call center automation on operational efficiency in healthcare,” Journal of Information Systems Engineering and Management, 2025. https://www.jisem-journal.com/index.php/journal/article/view/8901

Similar Articles

1-10 of 84

You may also start an advanced similarity search for this article.