<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">15</article-id>
      <article-id pub-id-type="doi">10.66424/2071-8217-2026-1-15</article-id>
      <title-group>
        <article-title>Use of large language models for security event analysis</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Использование больших языковых моделей в задачах анализа событий безопасности</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0003-4041-2317</contrib-id>
          <name>
            <surname>Tumakov</surname>
            <given-names>Maksim</given-names>
          </name>
          <email>tumbox2018@gmail.com</email>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Ivanova</surname>
            <given-names>Lyubov</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
        </contrib>
      </contrib-group>
      <aff id="aff1">Peter the Great St. Petersburg Polytechnic University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-03-30">
        <day>30</day>
        <month>03</month>
        <year>2026</year>
      </pub-date>
      <issue>1</issue>
      <fpage>201</fpage>
      <lpage>213</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2026_1_5-6.pdf"/>
      <abstract xml:lang="en">
        <p>As cyberattacks continue to rise and adversary techniques become more sophisticated, the workload on security monitoring and incident response teams in security operations centers increases substantially. Access to security events in existing telemetry storage systems still largely relies on queries written in specialized syntax, which does not always provide the required speed and depth of analysis. In parallel, large language models are rapidly evolving, enabling natural-language interaction with accumulated security logs. This paper proposes integrating a semantic large language models layer into an existing security event collection and processing architecture to retrieve relevant events by semantic similarity from natural-language queries. An implemented prototype is also described, demonstrating the technical feasibility of the approach using a locally deployed Mistral model and a web-based chatbot interface for SOC analysts, serving as a foundation for further development and operational adoption.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Security logs</kwd>
        <kwd>large language models (LLM)</kwd>
        <kwd>security operations center (SOC)</kwd>
        <kwd>semantic search</kwd>
        <kwd>security event analysis</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
