PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 23, 20262 citationsOpen Access

Autonomous SOC: A Multi-Agent LLM Architecture for Real-Time Cybersecurity Operations in Resource-Constrained Environments

View Full Paper
DXDong Nguyen Xuan

Key Points

  • The aim is to create an autonomous cybersecurity operations center that is affordable and effective for small and medium businesses.
  • Developed VRadar, a multi-agent SOC architecture using large language models.
  • Implemented five specialized AI agents to handle different SOC functions.
  • Evaluated the architecture with a real deployment processing 1.35 million security alerts.
  • Achieved a 91% autonomous resolution rate for security alerts.
  • Maintained an average confidence level of 87.5% in decisions made.
  • Reduced operational costs by approximately 97% compared to traditional human-operated SOCs.

Abstract

Security Operations Centers (SOCs) are critical infrastructure for cybersecurity defense, yet remain financially and operationally inaccessible to small and medium businesses (SMBs). We present VRadar, a novel multi-agent autonomous SOC architecture that leverages Large Language Models (LLMs) to replace traditional human-operated SOC workflows. Our system deploys five specialized AI agents — Operator, Care, Monitor, Optimizer, and Marketing — that work concurrently to perform alert triage, incident response, infrastructure monitoring, automated defense, and stakeholder communication. We evaluate our architecture on a production deployment processing 1.35 million security alerts across 11 tenants over 34 days, demonstrating that the multi-agent system achieves a 91% autonomous resolution rate with an average confidence of 87.5%, while reducing operational costs by approximately 97% compared to human-staffed SOC equivalents.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Dong Nguyen Xuan (2026) studied this question.

synapsesocial.com/papers/69c0e029fddb9876e79c1bc5https://doi.org/10.5281/zenodo.19151333
Ask AI
Helpful
Bookmark
Share
View Full Paper