AI-Augmented Network-Forensics: Leveraging LLMs for Real-Time Threat Detection and Automated Response in Enterprise Environments
Abstract
In modern enterprise networks, complicated rule-based signatures, fragmented alerts, encrypted traffic, and analyst workloads are delaying the ability to recognize and contain incidents, as the need grows for faster correlation of heterogeneous telemetry. This study evaluates an LLM-augmented network-forensics architecture for threat detection, evidence interpretation, and controlled automated response, while retaining deterministic security controls. The 30-day controlled digital-twin experiment in the medium-sized hybrid enterprise resulted in about 18.6 million security events. The events were correlated into 1,200 incident windows: 480 malicious and 720 benign. Precision, F1-score, Recall, FPR, ROC-AUC, investigation latency, and response accuracy were used to compare the proposed hybrid system with XGBoost, SIEM Rules, and a transformer-based anomaly detection architecture. In the controlled digital-twin evaluation, the LLM-augmented hybrid system achieved an F1 score of 94.2%, a false-positive rate of 3.1%, a mean detection time of 2.6 minutes, a mean response time of 13.4 minutes, and a response-recommendation accuracy of 92.1%. Through retrieval-augmented generation, either with or without schema validation, the amount of unsupported claims decreased from 14.6% to 3.8%. Results showed that LLM performance as contextual reasoning, explanation, and orchestration components in guarded workflows was most effective. For high-impact actions impacting critical assets, privileged identities, or production systems, human approval was required. Multi-enterprise validation, adversarial testing, and privacy-preserving model adaptation should be addressed in the future.
Keywords
References
Similar Articles
- Farhad Nouri, Dr. Mohammadreza Nouri, ADAPTIVE SIMILARITY-DRIVEN APPROACHES FOR CONTINUAL LEARNING: BRIDGING TASK-AWARE AND TASK-FREE PARADIGMS , International Journal of Advanced Artificial Intelligence Research: Vol. 2 No. 01 (2025): Volume 02 Issue 01
- Dr. Kenji Yamamoto, Prof. Lijuan Wang, LEVERAGING DEEP LEARNING IN SURVIVAL ANALYSIS FOR ENHANCED TIME-TO-EVENT PREDICTION , International Journal of Advanced Artificial Intelligence Research: Vol. 2 No. 05 (2025): Volume 02 Issue 05
- Mason Johnson, Forging Rich Multimodal Representations: A Survey of Contrastive Self-Supervised Learning , International Journal of Advanced Artificial Intelligence Research: Vol. 2 No. 11 (2025): Volume 02 Issue 11
- Ashis Ghosh, FAILURE-AWARE ARTIFICIAL INTELLIGENCE: DESIGNING SYSTEMS THAT DETECT, CATEGORIZE, AND RECOVER FROM OPERATIONAL FAILURES , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 01 (2026): Volume 03 Issue 01
- Mariam Nasr, A Contemporary Approach to Platform Synergy: Structured Context Sharing, Programmatic Connectivity Layers, and the Advancement of Intelligent Autonomous Systems , International Journal of Advanced Artificial Intelligence Research: Vol. 2 No. 11 (2025): Volume 02 Issue 11
- Dr. Elena M. Ruiz, Integrating Big Data Architectures and AI-Powered Analytics into Mergers & Acquisitions Due Diligence: A Theoretical Framework for Value Measurement, Risk Detection, and Strategic Decision-Making , International Journal of Advanced Artificial Intelligence Research: Vol. 2 No. 09 (2025): Volume 02 Issue 09
- Dr Chintal Kumar Patel, Survey of Artificial Intelligence Approaches for Traffic Accident Analysis, Prediction, And Prevention , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 07 (2026): Volume 03 Issue 07
- Sravan Kumar Nidiganti, A Systems-Level Framework for Evaluating Healthcare Ecosystem Quality, Complexity, and Member Outcomes , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 07 (2026): Volume 03 Issue 07
- Dr. Michael Lawson, Dr. Victor Almeida, Securing Deep Neural Networks: A Life-Cycle Perspective On Trojan Attacks And Defensive Measures , International Journal of Advanced Artificial Intelligence Research: Vol. 1 No. 01 (2024): Volume 01 Issue 01
- Dr. Rizky Pratama, Dr. Siti Maharani, A Multispectral Vegetation Index–Based Framework for Intelligent Tea Leaf Quality Assessment Using Degree of Polarization, Leaf Area Index, Photosynthetically Active Radiation, and NDVI Analysis , International Journal of Advanced Artificial Intelligence Research: Vol. 3 No. 08 (2026): Volume 03 Issue 08
You may also start an advanced similarity search for this article.