Abstract
With the continuous evolution of cyber threats and the growing complexity of enterprise IT infrastructures, traditional Security Operations Centers (SOCs) face challenges such as alert overload, talent shortages, and the limitations of rule-based engines. Large-model technology (LMT) provides a new pathway toward intelligent and automated security operations. This study analyzes key techniques - including the Transformer architecture, the pre-training and fine-tuning paradigm, and multimodal learning - and validates their effectiveness through practical case studies in industries such as finance and manufacturing. Empirical results show that the LMT-based system reduced average alert triage time from 60 minutes to 8 minutes (-87%), increased daily alert handling capacity from 200 to 800 cases (+300%), and improved detection performance from Precision/Recall/F1 = 75%/70%/0.72 to 92%/88%/0.90, demonstrating its ability to accelerate incident response, enhance detection accuracy, and optimize SOC efficiency. At the same time, the study discusses challenges such as data privacy, model hallucinations, and interpretability, and proposes corresponding solutions, providing both theoretical and practical insights for advancing enterprise security operations toward intelligence, autonomy, and cost-effectiveness.
Author supplied keywords
Cite
CITATION STYLE
Li, L., Wang, T., An, Q., & Dong, J. (2025). Research on Enterprise Security Operation Based on Large Model Technology. In Proceedings of 2025 8th International Conference on Computer Information Science and Artificial Intelligence, CISAI 2025 (pp. 1587–1593). Association for Computing Machinery, Inc. https://doi.org/10.1145/3773365.3773614
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.