📄 Sciences Methods and Technologies
International Journal (SciMeTech)

Volume 2 · Issue 1 · 2026
ISSN: 3085-5284
AI-Augmented Security Operations: A Unified Framework for Intelligent Threat Detection in Enterprise Environments
Mahesh Puthenpurakal Gopalakrishnan
Pages 216–227 · Principal Consultant - Cybersecurity, Infosys Limited Americas · CISSP, CISA, CCSP, CISM, CRISC, CGRC, CEH, ISO 27001 LA, AAISM
Abstract
Security Operations Centers (SOCs) are facing a structural crisis driven by rising alert volumes, increasingly sophisticated adversaries, and analyst fatigue. Despite significant investment in SIEM platforms and rule-based detection systems, IBM's Cost of a Data Breach Report 2023 indicates that the average breach still requires 197 days to identify [1]. The root cause is clear: SOC failure is primarily architectural in nature, not operational — organizations have invested in the right people and processes, but the underlying detection architecture is no longer fit for purpose.

This paper presents a practitioner-driven framework for AI-augmented SOC transformation based on three operational pillars: Asset Visibility, Detection Engineering, and Accelerated Remediation. The proposed approach integrates traditional cybersecurity frameworks (MITRE ATT&CK, NIST RMF, OWASP Top 10) with emerging AI-focused frameworks (MITRE ATLAS, NIST AI RMF, OWASP LLM Top 10, OWASP MCP Top 10), creating a unified detection and governance model capable of addressing both conventional and AI-driven threats.

A comparative detection model is introduced to evaluate SOC performance across traditional, AI-enabled, and hybrid architectures. The analysis demonstrates that neither rule-based SOCs nor standalone AI-driven SOCs are sufficient in isolation due to limitations such as detection gaps, bias, hallucination, and lack of contextual confidence. The proposed hybrid model—combining traditional detection logic, AI augmentation, and Human-in-the-Loop (HITL) decision-making—achieves significantly improved detection fidelity, reduced false positives, and faster response cycles.

Results from a controlled scenario-based validation demonstrate measurable improvements in Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), and analyst workload reduction.
Keywords: Security Operations Center, AI-Augmented SOC, MTTD / MTTR, MITRE ATLAS, NIST AI RMF, OWASP Top 10 LLM, Detection Engineering, SOAR / UEBA, Alert Fatigue, Control Self-Assessment, Cyber Resilience, HITL

References

  1. IBM Security. (2023). Cost of a Data Breach Report 2023. IBM Corporation. https://www.ibm.com/reports/database
  2. SANS Institute. (2023). 2023 SOC Survey: Evolving the Analyst Role. SANS Reading Room. https://www.sans.org
  3. Gartner. (2023). Market Guide for Managed Detection and Response Services. Gartner Research.
  4. MITRE Corporation. (2023). ATT&CK Framework: A Knowledge Base of Adversary Tactics and Techniques. https://attack.mitre.org/
  5. NIST. (2025). Computer Security Incident Handling Guide (SP 800-61 Rev. 3). National Institute of Standards and Technology.
  6. CISA. (2023). Cybersecurity Best Practices. Cybersecurity and Infrastructure Security Agency. https://www.cisa.gov/cybersecurity-best-practices
  7. Binbshr, F., Imam, M., Ghaleb, M., Hamdan, M., Rahim, M. A., & Hammoudeh, M. (2023). The Rise of Cognitive SOCs: A Systematic Literature Review on AI Approaches. IEEE Access, 11.
  8. Ali, N., & Wallace, G. (2023). The Future of SOC Operations: Autonomous Cyber Defense with AI and Machine Learning. Journal of Cybersecurity Research.
  9. MITRE Corporation. (2023). ATLAS: Adversarial Threat Landscape for Artificial-Intelligence Systems. https://atlas.mitre.org/
  10. OWASP. (2023). OWASP Top 10 for Large Language Model Applications. OWASP Foundation. https://owasp.org/www-project-top-10-for-large-language-model-applications/
  11. NIST. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0), AI 100-1. National Institute of Standards and Technology.
  12. OWASP. (2025). OWASP Top 10 for Model Context Protocol (MCP). OWASP Foundation. https://owasp.org/www-project-top-10-for-model-context-protocol/
  13. Sharma, A., & Spunda, R. (2023). SOC Optimization Through AI-Powered Automation and Blockchain Integration. IEEE Security & Privacy.
  14. Gill, S., & Noah, A. (2023). AI-Enhanced SOC Operations: From Threat Intelligence to Automated Mitigation. International Journal of Information Security.
  15. Ponemon Institute. (2023). The Economics of Security Operations Centers. Ponemon Institute Research.