AI-REASON

AI-REASON – AI-assisted Reliable and Explainable Analysis for Security OperatioNs – strengthens Swedish industry’s ability to detect, analyze, and respond to cybersecurity threats. By developing an AI-assisted decision support system for security monitoring, the project supports SOC analysts with more reliable, explainable, and timely incident assessment.

Facts
School: Tekniska Högskolan
Time: 2026-2028
Partners:
Dizparc Security Solutions
Financer: Vinnova / Advanced Digitalization
Researchers:
Görkem Kilinc Soylu, Assistant Professor
Neziha Akalin, Assistant Professor
Maria Riveiro, Professor
Erik Bergström, Associate Professor
To be recruited, PhD student
AI-REASON aims to develop a proof-of-concept AI-based decision support system for security operations. The system will combine deterministic IoC-based (Indicator of Compromise) detection, behavior-based machine learning, and AI-driven reasoning to help Security Operation Center (SOC) analysts assess alerts, reduce false positives, and generate explainable reports with concrete recommendations.
A growing challenge for industrial cybersecurity
Swedish industrial systems are becoming increasingly digitalized and interconnected through cloud platforms, enterprise IT environments, industrial control systems, and supply-chain integrations. This creates new opportunities for efficiency and flexibility, but also increases dependence on a reliable and secure digital infrastructure.
Cybersecurity incidents are therefore no longer isolated technical problems. They can quickly affect production continuity, service delivery, safety, and trust across industrial operations and value chains. SOCs play a central role in managing these risks, but analysts often need to make time-critical decisions based on large volumes of fragmented information.
AI-supported security analysis
AI-REASON focuses on improving how SOC analysts detect, triage, and understand potential security incidents. Traditional rule-based security monitoring often generates large numbers of false positives, contributing to alarm fatigue and increasing the risk of missing real threats.
The project will develop an AI-assisted prototype that collects and contextualizes security-relevant data, reconstructs attack timelines, and generates explainable incident assessments. The system will use known IoC, machine-learning-based behavior analysis, and reasoning AI to assess whether an anomaly is likely to pose a real threat.
The prototype will be designed for integration with existing Security Information and Event Management systems and tested in realistic SOC environments.
Human-in-the-loop feedback is central to the project. SOC analysts will review incidents and classify them as true or false positives, allowing the system to learn from previous cases and continuously improve detection, triage, and explanation quality.
Increased resilience and reduced workload
The goal is not to replace SOC analysts, but to strengthen their ability to prioritize alerts, understand incident context, and make faster and more consistent decisions under pressure. The results will be useful to SOC operators and companies that need more scalable, effective cybersecurity monitoring. By reducing false positives, improving incident understanding, and supporting explainable decision-making, AI-REASON contributes to stronger digital resilience and more dependable industrial operations.
The project will also generate new knowledge on how to combine deterministic detection, machine learning, explainable AI, and human feedback in practical security operations.
Want to know more?
- Universitetslektor Datavetenskap
- Tekniska Högskolan
- gorkem.kilinc.soylu@ju.se