AI-Driven SIEM (Security Information and Event Management) Systems Using Long Short-Term Memory (LSTM) for Log-Based Threat Detection

Surbhi Choudhary, S. Kalaiarasi, A Joshua Sundar Raja · 2025

The increasing sophistication of cyber threats necessitates the adoption of advanced techniques for real-time anomaly detection in Security Information and Event Management (SIEM) systems. Traditional rule-based and signature-based approaches are no longer sufficient to address emerging attack vectors and the growing volume of security logs. This chapter explores the integration of Long Short-Term Memory (LSTM) networks into SIEM systems for log-based threat detection, highlighting their capacity to capture temporal dependencies and identify subtle patterns in sequential log data. Despite their effectiveness, challenges such as data privacy concerns, limited access to high-quality labeled datasets, and computational complexity remain. To overcome these obstacles, privacy-preserving data synthesis techniques, such as Generative Adversarial Networks (GANs) and differential privacy, are proposed to generate realistic, high-quality synthetic datasets for model training, ensuring data confidentiality and regulatory compliance. The chapter discusses the potential of LSTM-based SIEM systems in enhancing cybersecurity defenses, as well as ongoing research efforts to address the scalability, accuracy, and interpretability of AI-driven models. Key research gaps and future directions in the application of LSTM to SIEM are also presented. This work provides valuable insights into the development of next-generation AI-driven cybersecurity solutions that can dynamically adapt to the evolving threat landscape.

Read the paper · More papers on PaperTik