About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
sis 26(3):

Editorial

Playbook-Guided Executable SOC Automation for Privacy-Preserving Response in Distributed Networked Systems

Download5 downloads
Cite
BibTeX Plain Text
  • @ARTICLE{10.4108/eetsis.13946,
        author={Jie Zhang and Haizhuang Liu and Le Ren and Yuxiang Zhao and Zekai Song},
        title={Playbook-Guided Executable SOC Automation for Privacy-Preserving Response in Distributed Networked Systems},
        journal={EAI Endorsed Transactions on Scalable Information Systems},
        volume={13},
        number={3},
        publisher={EAI},
        journal_a={SIS},
        year={2026},
        month={9},
        keywords={executable SOC automation, playbook-guided response, privacy-preserving response, distributed networked systems, multi-agent SOC, SOAR orchestration},
        doi={10.4108/eetsis.13946}
    }
    
  • Jie Zhang
    Haizhuang Liu
    Le Ren
    Yuxiang Zhao
    Zekai Song
    Year: 2026
    Playbook-Guided Executable SOC Automation for Privacy-Preserving Response in Distributed Networked Systems
    SIS
    EAI
    DOI: 10.4108/eetsis.13946
Jie Zhang1, Haizhuang Liu1,*, Le Ren1, Yuxiang Zhao1, Zekai Song1
  • 1: State Grid Shandong Electric Power Company (China)
*Contact email: 953943390@qq.com

Abstract

INTRODUCTION: Distributed networks require security operations center (SOC) automation that connects data security monitoring, privacy-aware evidence handling, controlled execution, and measurable evidence. Static playbooks cannot fully handle ambiguous cross-domain incident context. OBJECTIVES: This paper presents an executable multi-agent framework for data security monitoring and response in distributed networks. METHODS: LLM-based roles generate event analysis, tasks, actions, commands, execution records, and summaries. Security orchestration, automation, and response (SOAR) playbooks and a virtual security capability layer provide controlled execution and repeatable evaluation. RESULTS: On 83 labeled incidents, the framework achieved 0.9684 precision, 0.4742 recall, 0.6367 F1-score, and 76.45 s average handling time for tool-call evaluation. CONCLUSION: The framework makes distributed data-security response auditable and quantitatively evaluable. The main improvement direction is stronger planning verification for complex multi-step incidents.

Keywords
executable SOC automation, playbook-guided response, privacy-preserving response, distributed networked systems, multi-agent SOC, SOAR orchestration
Received
2026-07-08
Accepted
2026-08-03
Published
2026-09-03
Publisher
EAI
http://dx.doi.org/10.4108/eetsis.13946

Copyright © 2026 Jie Zhang et al., licensed to EAI. This is an open access article distributed under the terms of the CC BY-NC-SA 4.0, which permits copying, redistributing, remixing, transformation, and building upon the material in any medium so long as the original work is properly cited.

EBSCOProQuestDBLPDOAJPortico
EAI Logo

About EAI

  • Who We Are
  • Leadership
  • Research Areas
  • Partners
  • Media Center
  • Cookie Preferences

Community

  • Membership
  • Conference
  • Recognition
  • Sponsor Us

Publish with EAI

  • Publishing
  • Journals
  • Proceedings
  • Books
  • EUDL