Playbook-Guided Executable SOC Automation for Privacy-Preserving Response in Distributed Networked Systems
DOI:
https://doi.org/10.4108/eetsis.13946Keywords:
executable SOC automation, playbook-guided response, privacy-preserving response, distributed networked systems, multi-agent SOC, SOAR orchestrationAbstract
INTRODUCTION: Distributed networks require security operations center (SOC) automation that connects data security monitoring, privacy-aware evidence handling, controlled execution, and measurable evidence. Static playbooks cannot fully handle ambiguous cross-domain incident context.
OBJECTIVES: This paper presents an executable multi-agent framework for data security monitoring and response in distributed networks.
METHODS: LLM-based roles generate event analysis, tasks, actions, commands, execution records, and summaries. Security orchestration, automation, and response (SOAR) playbooks and a virtual security capability layer provide controlled execution and repeatable evaluation.
RESULTS: On 83 labeled incidents, the framework achieved 0.9684 precision, 0.4742 recall, 0.6367 F1-score, and 76.45 s average handling time for tool-call evaluation.
CONCLUSION: The framework makes distributed data-security response auditable and quantitatively evaluable. The main improvement direction is stronger planning verification for complex multi-step incidents.
References
[1] Cichonski, P., Millar, T., Grance, T. and Scarfone, K. (2012) Computer Security Incident Handling Guide. Nist special publication 800-61 revision 2, National Institute of Standards and Technology. doi:10.6028/NIST.SP.800-61r2, URL https://doi.org/10.6028/NIST.SP.800-61r2.
[2] Verizon Business (2026) 2026 Data Breach Investigations Report. Tech. rep., Verizon Business. URL https://www.verizon.com/business/resources/reports/dbir/.
[3] Tariq, S., Chhetri, M.B., Nepal, S. and Paris, C. (2025) Alert fatigue in security operations centres: Research challenges and opportunities. ACM Computing Surveys 57(9): 224. doi:10.1145/3723158.
[4] Cybersecurity and Infrastructure Security Agency (2021) Federal Government Cybersecurity Incident and Vulnerability Response Playbooks. Tech. rep., CISA.
[5] OASIS (2023) CACAO Security Playbooks Version 2.0, OASIS. URL https://docs.oasis-open.org/cacao/security-playbooks/v2.0/security-playbooks-v2.0.html.
[6] Hu, H., Zhang, L., Zhang, Z., Yao, X. and Wu, X. (2025) An intelligent playbook recommendation algorithm based on dynamic interest modeling for soar. Symmetry 17(11): 1851. doi:10.3390/sym17111851.
[7] Habibzadeh, A., Feyzi, F. and Atani, R.E. (2025), Large language models for security operations centers: A comprehensive survey, arXiv preprint arXiv:2509.10858. doi:10.48550/arXiv.2509.10858, URL https://arxiv.org/abs/2509.10858.
[8] Jaffal, N.O., Alkhanafseh, M. and Mohaisen, D. (2025), Large language models in cybersecurity: A survey of applications, vulnerabilities, and defense techniques, arXiv preprint arXiv:2507.13629. doi:10.48550/arXiv.2507.13629, URL https://arxiv.org/abs/2507.13629.
[9] Xu, H. et al. (2025) Large language models for cyber security: A systematic literature review. ACM Transactions on Software Engineering and Methodology doi:10.1145/3769676.
[10] Xi, Z., Chen, W., Guo, X. et al. (2025) The rise and potential of large language model based agents: A survey. Science China Information Sciences 68(2): 121101. doi:10.1007/s11432-024-4222-0.
[11] Akbari Gurabi, M., Fysarakis, K., Mavroeidis, V. et al. (2026) From legacy to standard: Llm-assisted transformation of cybersecurity playbooks into cacao format. In Computer Security. ESORICS 2025 International Workshops (Springer Nature Switzerland), 491–510. doi:10.1007/978-3-032-16092-8_27.
[12] Wu, Q., Bansal, G., Zhang, J. et al. (2023), Autogen: Enabling next-gen llm applications via multi-agent conversation framework, arXiv preprint arXiv:2308.08155. doi:10.48550/arXiv.2308.08155, URL https://arxiv.org/abs/2308.08155.
[13] Yao, S., Zhao, J., Yu, D. et al. (2023) React: Synergizing reasoning and acting in language models. In International Conference on Learning Representations. URL https://arxiv.org/abs/2210.03629.
[14] Liu, Z. (2024), Multi-agent collaboration in incident response with large language models, arXiv preprint arXiv:2412.00652. doi:10.48550/arXiv.2412.00652, URL https://arxiv.org/abs/2412.00652.
[15] Yu, M., Meng, F., Zhou, X., Wang, S. et al. (2025), A survey on trustworthy llm agents: Threats and countermeasures, arXiv preprint arXiv:2503.09648. doi:10.48550/arXiv.2503.09648, URL https://arxiv.org/abs/2503.09648.
[16] Li, M., Zhao, Y., Yu, B. et al. (2023), Apibank: A comprehensive benchmark for tool-augmented llms, arXiv preprint arXiv:2304.08244. doi:10.48550/arXiv.2304.08244, URL https://arxiv.org/abs/2304.08244.
[17] Qin, Y., Liang, S., Ye, Y. et al. (2024) Toolllm: Facilitating large language models to master 16000+ real-world apis. In International Conference on Learning Representations. URL https://arxiv.org/abs/2307.16789.
[18] Wang, J., Zhou, J., Wen, M. et al. (2024), Hammerbench: Fine-grained function-calling evaluation in real mobile device scenarios, arXiv preprint arXiv:2412.16516. doi:10.48550/arXiv.2412.16516, URL https://arxiv.org/abs/2412.16516.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Jie Zhang, Haizhuang Liu, Le Ren, Yuxiang Zhao, Zekai Song

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
This is an open access article distributed under the terms of the CC BY-NC-SA 4.0, which permits copying, redistributing, remixing, transformation, and building upon the material in any medium so long as the original work is properly cited.