3 papers
cs.CR2026
NLLog: Lightweight, Explainable SOC Anomaly Detection via Log-to-Language Rewriting
Samuel Ndichu, Tao Ban, Seiichi Ozawa +2
System-generated logs underpin security monitoring, yet their rigid template-based format hinders both automated analysis and human comprehension. We present NLLog (Natural-Languag…
cs.CR2026
PACT: Reducing Alert Fatigue in Low-Prevalence SOC Streams with Triggered Active Learning
Samuel Ndichu, Tao Ban, Seiichi Ozawa +2
Security operations centers face persistent alert fatigue: in low-prevalence streams, even low false-positive rates generate substantial investigation load, while aggregate F1 scor…
cs.CR2026
AI-Driven Security Alert Screening and Alert Fatigue Mitigation in Security Operations Centers: A Survey
Samuel Ndichu, Tao Ban, Seiichi Ozawa +2
Security alert screening is the downstream task of filtering, prioritizing, correlating, and contextualizing alerts for analyst attention in Security Operations Centers. This surve…