AI-Augmented Network-Forensics: Leveraging LLMs for Real-Time Threat Detection and Automated Response in Enterprise Environments
Abstract
In modern enterprise networks, complicated rule-based signatures, fragmented alerts, encrypted traffic, and analyst workloads are delaying the ability to recognize and contain incidents, as the need grows for faster correlation of heterogeneous telemetry. This study evaluates an LLM-augmented network-forensics architecture for threat detection, evidence interpretation, and controlled automated response, while retaining deterministic security controls. The 30-day controlled digital-twin experiment in the medium-sized hybrid enterprise resulted in about 18.6 million security events. The events were correlated into 1,200 incident windows: 480 malicious and 720 benign. Precision, F1-score, Recall, FPR, ROC-AUC, investigation latency, and response accuracy were used to compare the proposed hybrid system with XGBoost, SIEM Rules, and a transformer-based anomaly detection architecture. In the controlled digital-twin evaluation, the LLM-augmented hybrid system achieved an F1 score of 94.2%, a false-positive rate of 3.1%, a mean detection time of 2.6 minutes, a mean response time of 13.4 minutes, and a response-recommendation accuracy of 92.1%. Through retrieval-augmented generation, either with or without schema validation, the amount of unsupported claims decreased from 14.6% to 3.8%. Results showed that LLM performance as contextual reasoning, explanation, and orchestration components in guarded workflows was most effective. For high-impact actions impacting critical assets, privileged identities, or production systems, human approval was required. Multi-enterprise validation, adversarial testing, and privacy-preserving model adaptation should be addressed in the future.
Keywords
References
Similar Articles
- Dr. Amir Reza Khosravi, Dr. Sara Mohammadi, Advanced Cognitive State Analysis of Insomnia Using Computational Architecture for Modeling Thought and Awareness Disruption , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 05 (2026): Volume 03 Issue 05
- Grigorii Danileiko, Formal Operational Models for Protecting Web Interfaces of Legal LLM Systems from Prompt Injection and Insecure Output Handling , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 05 (2026): Volume 03 Issue 05
- Dr. Erion Hoxha, Dr. Elira Dervishi, Global Firefly Optimization Model for IoT Attack Detection , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 08 (2026): Volume 03 Issue 08
- Dr. Alessia Romano, Prof. Marco Bianchi, DEVELOPING AI ASSISTANCE FOR INCLUSIVE COMMUNICATION IN ITALIAN FORMAL WRITING , International Journal of Advanced Artificial Intelligence Research: Vol. 1 No. 01 (2024): Volume 01 Issue 01
- Leon Ficsher, Resilient Embedded Architectures for Safety-Critical Automotive Systems: Integrating Lockstep Fault Tolerance, Cybersecurity Assurance, And Software-Defined Platforms , International Journal of Advanced Artificial Intelligence Research: Vol. 1 No. 01 (2024): Volume 01 Issue 01
- Dr. Elias A. Petrova, AN EDGE-INTELLIGENT STRATEGY FOR ULTRA-LOW-LATENCY MONITORING: LEVERAGING MOBILENET COMPRESSION AND OPTIMIZED EDGE COMPUTING ARCHITECTURES , International Journal of Advanced Artificial Intelligence Research: Vol. 2 No. 10 (2025): Volume 02 Issue 10
- Elena Volkova, Emily Smith, INVESTIGATING DATA GENERATION STRATEGIES FOR LEARNING HEURISTIC FUNCTIONS IN CLASSICAL PLANNING , International Journal of Advanced Artificial Intelligence Research: Vol. 2 No. 04 (2025): Volume 02 Issue 04
- Adrian T. Blackmoor, Digital Lending Transformation Through Real Time Artificial Intelligence Based Credit Analytics , International Journal of Advanced Artificial Intelligence Research: Vol. 2 No. 11 (2025): Volume 02 Issue 11
- Ronak Jani, Automated Monitoring and Self-Healing Mechanisms in High-Availability Cloud Databases , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 04 (2026): Volume 03 Issue 04
- Nabeel Ehsan, Deep Learning for Continuous Auditing & Real-Time Assurance , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 04 (2026): Volume 03 Issue 04
You may also start an advanced similarity search for this article.