Review of Detection and Prevention Techniques for Cyberattacks in SOCs: State of the Art and Future Challenges
Imane Lotfi, Meriem Mandar · 2025
Due to the increasing quantity and complexity of cyberattacks, Security Operations Centers (SOC) are struggling to secure IT infrastructures. Moreover, traditional detection methods work effectively on known threats but are unable to combat unknown types of attacks, such as zero-day vulnerabilities. Therefore, the incorporation of Machine Learning, particularly for detection, offers appropriate recognition of attacks, whether they are already listed or emerging. Nevertheless, a number of problems remain, particularly a high rate of false positives. Therefore, this research attempts to address this difficulty and presents a new decision-making approach leveraging Machine Learning to optimize detection strategies through this article. this approach improves threat detection decision-making and reduces false positives by adopting a hybrid approach that combines several Machine Learning models, notably XGBoost for detecting known threats, AutoEncoder-GNN for detecting unknown threats, CNN-transformer for in-depth threat analysis and effective detection, and finally LLM (Large Language Model) for analysis and decision-making. This scalable and adaptable approach will improve the detection and prevention of cyber threats in SOCs and meet the needs of modern forms of cybersecurity.