inklap

DEVELOPMENT OF AN AGENT FOR NOTIFICATION ANALYSIS BASED ON ARTIFICIAL INTELLIGENCE USING N8N AND ELASTIC SECURITY SOFTWARE

Oleksandr Volotovskyi, Roman Banakh, Andrian Piskozub · Cybersecurity: Education, Science, Technique · 2025

This article presents a research-driven approach to enhancing the efficiency of incident response within Security Operations Centers by implementing an automated event analysis system that integrates the n8n platform and large language models. This approach addresses modern cybersecurity challenges, including the continuous increase in the number of security alerts, the growing complexity of IT infrastructures, limited human resources, and the declining effectiveness of manual analysis. The developed architecture incorporates the Elastic Security SIEM system as the primary event source, n8n as the orchestration platform for workflow management, LLM-based agents for natural-language interpretation of incidents, and external enrichment services such as AbuseIPDB and VirusTotal. The core system functions include automated collection, normalization, and enrichment of security events, risk scoring, incident type classification, generation of concise analytical summaries in the 5W format (Who, What, When, Where, Why), and automatic creation of relevant response actions. To validate the effectiveness of the proposed approach, a comprehensive experimental study was conducted, encompassing

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً