Graph-Augmented LLMs for SIEM: Explainable Attack Attribution with High-Fidelity Log Reduction
Keywords:
SIEM, Telemetry Analysis, Graph Neural Networks, Large Language Models, Cyber Threat Detection, Explainable AI, Security Analytics, Anomaly Detection.Abstract
Security Information and Event Management (SIEM) systems have become the core component of modern cybersecurity operations, providing centralized monitoring, correlation and analysis of security events in distributed infrastructures. However, traditional SIEM platforms are heavily based on signature-based and rule-driven techniques which are not capable of detecting advanced multi-stage attacks and zero-day exploits. These systems also suffer from the problem of alert fatigue due to high false positive rates and lack of contextual reasoning capabilities. We propose a SIEM framework, named Graph-Augmented Large Language Model (GA-LLM), which integrates Graph Machine Learning (Graph ML) and Large Language Models (LLMs) for intelligent telemetry inspection. The framework constructs a dynamic, heterogeneous interaction graph from telemetry sources, and applies Graph Neural Networks (GNNs) to identify anomalous patterns of behavior. Then, an LLM reasoning engine provides semantic interpretation, attack attribution, and explainable insights by putting these anomalies into context. The proposed system shows improved detection accuracy and contextual awareness, together with a reduction in false positives relative to traditional and machine-learning-based baselines. The experimental validation shows a significant improvement over traditional and ML-based SIEM systems and provides a viable solution for next-generation Security Operations Centers (SOCs).





