AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
PDF (2.8 MB)
Collect
Submit Manuscript AI Chat Paper
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Article | Open Access

Logic-Aware Security Playbook Generation for SOAR Using Adversarial Representation Learning

Hangyu Hu1Liangrui Zhang1Xiaowei Huang1Xingmiao Yao1,2( )Youyang Qu3Xia Wu1Guangmin Hu1,2
School of Information and Communication Engineering, University of Electronic Science and Technology of China, Chengdu, China
School of Resources and Environment, University of Electronic Science and Technology of China, Chengdu, China
Shandong Computer Science Center, Qilu University of Technology (Shandong Academy of Sciences), Jinan, China
Show Author Information

Abstract

With the evolution of information technology toward more advanced intelligence and automation, Security Orchestration, Automation, and Response (SOAR) has become a critical foundation for security incident handling, owing to its intelligent orchestration capabilities. Security playbooks, as the core mechanism for automated response in SOAR, require well-designed workflows and precise action matching to ensure efficient and accurate alert handling. However, with the rising sophistication of attacks and the expanding scale of security alerts, traditional expert-driven playbook recommendation approaches often degrade in recommendation quality or completely fail when existing playbook repositories cannot adequately cover unknown or novel alert scenarios. Generative Adversarial Network (GAN) offers a promising solution by capturing feature associations from existing playbooks and autonomously generating validated new playbooks tailored to previously unseen alert characteristics. Motivated by this, we propose a logic-aware, two-stage GAN-based playbook generation method in this paper. In the first stage, alert features are projected into a modeled playbook feature space to perform preliminary similarity matching. In the second stage, a hybrid strategy combining similarity-based recommendation and GAN-driven generation is used to produce and refine playbooks while preserving logical workflow integrity. Experimental results demonstrate that the proposed approach not only delivers high-precision playbook recommendations for known alert scenarios but also efficiently generates reliable playbooks for unseen alerts, achieving an average alert handling success rate of 86.55%, and thereby fulfilling response requirements in previously uncovered scenarios.

References

【1】
【1】
 
 
Computers, Materials & Continua
Article number: 50

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Hu H, Zhang L, Huang X, et al. Logic-Aware Security Playbook Generation for SOAR Using Adversarial Representation Learning. Computers, Materials & Continua, 2026, 88(3): 50. https://doi.org/10.32604/cmc.2026.081752

6

Views

0

Downloads

0

Crossref

0

Web of Science

0

Scopus

Received: 08 March 2026
Accepted: 15 May 2026
Published: 23 July 2026
© The Author 2026.

This work is licensed under a Creative Commons Attribution 4.0 International License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.