International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1720191

1720191 Vol 10 · Issue 1 Download Paper

AI-Powered Cyber Threat Detection and Automated Incident Response

Darshankumar Jaysukh Dhanani

Subject area: Science,Engineering and Technology  ·  Area of research: Artificial Intelligence

DOI: https://doi.org/10.64388/IREV10I1-1720191

Abstract

As the volume, speed and sophistication of cyberattacks continue to increase, the ability of traditional signature-based and manually-operated security controls has not kept up, which is leading to the broad use of artificial intelligence (AI) throughout the cybersecurity lifecycle. This paper summarizes the latest advances in intrusion detection, explainable AI, ransomware and phishing detection, and security orchestration, automation, and response (SOAR) platforms and their role in cyber threat detection and automated incident response. The methodology employed in this literature review was narrative because it enabled identification and synthesis of peer-reviewed literature and authoritative technical standards of machine learning, deep learning and agentic artificial intelligence applications in security operations. The review concludes that AI-based detection systems consistently beat traditional rule-based detection systems on both reported accuracy and false positive metrics, explainability is emerging as a central requirement to enable analysts to build trust in the technology and to ensure regulatory compliance, and automation of incident response, especially with SOAR and new agentic architectures, significantly lowers mean time to containment and analyst workload. Meanwhile, the review outlines ongoing challenges such as combating adversarial use of AI models, addressing data quality issues, handling the complexity of integrating AI systems, and the ongoing need for human oversight. The paper argues that the auto-D&A should be used as an asset to augment human security analysts and not supplant them, and provides tips for companies looking to implement these technologies in responsible ways.

Keywords

Artificial Intelligence, Cyber Threat Detection, Automated Incident Response, Machine Learning, Security Orchestration, Explainable AI

References

[1] Alauthman, M., Aslam, N., Al-Qerem, A., Aldweesh, A., & Sureephong, P. (2026). Generative adversarial networks for intrusion detection systems: A comprehensive survey of applications, challenges, and research directions. Arabian Journal for Science and Engineering. https://doi.org/10.1007/s13369-026-11103-6

[2] Aljahdali, A. O., & Alsulami, R. (2025). Streamlining threat response and automating critical use cases with security orchestration, automation and response (SOAR). Journal of Digital Security and Forensics, 2(1), 36–57. https://doi.org/10.29121/digisecforensics.v2.i1.2025.45

[3] Chen, Y., Cui, M., Wang, D., Cao, Y., Yang, P., Jiang, B., Lu, Z., & Liu, B. (2024). A survey of large language models for cyber threat detection. Computers & Security, 145, 104016. https://doi.org/10.1016/j.cose.2024.104016

[4] Ferrag, M. A., Friha, O., Maglaras, L., Janicke, H., & Shu, L. (2021). Federated deep learning for cyber security in the internet of things: Concepts, applications, and experimental analysis. IEEE Access, 9, 138509–138542. https://doi.org/10.1109/ACCESS.2021.3118642

[5] IBM. (2025). Cost of a data breach report 2025. IBM Security.

[6] Ismail, Kurnia, R., Brata, Z. A., Nelistiani, G. A., Heo, S., Kim, H., & Kim, H. (2025). Toward robust security orchestration and automated response in security operations centers with a hyper-automation approach using agentic artificial intelligence. Information, 16(5), 365. https://doi.org/10.3390/info16050365

[7] Ispahany, J., Islam, M. R., Islam, M. Z., & Khan, M. A. (2024). Ransomware detection using machine learning: A review, research limitations and future directions. IEEE Access, 12, 68785–68813. https://doi.org/10.1109/ACCESS.2024.3397921

[8] Khan, N., Ahmad, K., Al Tamimi, A., Alani, M. M., Bermak, A., & Khalil, I. (2025). Explainable AI-based intrusion detection systems for Industry 5.0 and adversarial XAI: A systematic review. Information, 16(12), 1036. https://doi.org/10.3390/info16121036

[9] Khraisat, A., & Alazab, A. (2021). A critical review of intrusion detection systems in the internet of things: Techniques, deployment strategy, validation strategy, attacks, public datasets and challenges. Cybersecurity, 4(1), Article 18. https://doi.org/10.1186/s42400-021-00077-7

[10] Lansky, J., Ali, S., Mohammadi, M., Majeed, M. K., Karim, S. H. T., Rashidi, S., Hosseinzadeh, M., & Rahmani, A. M. (2021). Deep learning-based intrusion detection systems: A systematic review. IEEE Access, 9, 101574–101599. https://doi.org/10.1109/ACCESS.2021.3097247

[11] Liu, H., & Lang, B. (2019). Machine learning and deep learning methods for intrusion detection systems: A survey. Applied Sciences, 9(20), 4396. https://doi.org/10.3390/app9204396

[12] Macas, M., Wu, C., & Fuertes, W. (2024). Adversarial examples: A survey of attacks and defenses in deep learning-enabled cybersecurity systems. Expert Systems with Applications, 238, 122223. https://doi.org/10.1016/j.eswa.2023.122223

[13] Moustafa, N., Hu, J., & Slay, J. (2019). A holistic review of network anomaly detection systems: A comprehensive survey. Journal of Network and Computer Applications, 128, 33–55. https://doi.org/10.1016/j.jnca.2018.12.006

[14] National Institute of Standards and Technology. (2025). Incident response recommendations and considerations for cybersecurity risk management: A CSF 2.0 community profile (NIST Special Publication 800-61, Rev. 3). U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-61r3

[15] Nnaka, K. I., Mbamalu, P. O., Nwaigbo, J. C., Ozo-ogueji, P. C., Njoku, V. I., & Ekechi, C. C. (2025). AI-powered threat detection: Opportunities and limitations in modern cyber defense. World Journal of Advanced Research and Reviews, 27(2), 210–223. https://doi.org/10.30574/wjarr.2025.27.2.2854

[16] Nobles, C. (2022). Stress, burnout, and security fatigue in cybersecurity: A human factors problem. Holistica Journal of Business and Public Administration, 13(1), 49–72. https://doi.org/10.2478/hjbpa-2022-0003

[17] Pinto, A., Herrera, L.-C., Donoso, Y., & Gutierrez, J. A. (2023). Survey on intrusion detection systems based on machine learning techniques for the protection of critical infrastructure. Sensors, 23(5), 2415. https://doi.org/10.3390/s23052415

[18] Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207

[19] Tariq, S., Baruwal Chhetri, M., Nepal, S., & Paris, C. (2025). Alert fatigue in security operations centres: Research challenges and opportunities. ACM Computing Surveys, 57(9), 1–38. https://doi.org/10.1145/3723158

[20] Thakur, K., Ali, M. L., Obaidat, M. A., & Kamruzzaman, A. (2023). A systematic review on deep-learning-based phishing email detection. Electronics, 12(21), 4545. https://doi.org/10.3390/electronics12214545

How to cite this paper

Darshankumar Jaysukh Dhanani "AI-Powered Cyber Threat Detection and Automated Incident Response" Iconic Research And Engineering Journals Volume 10 Issue 1 2026 Page 3043-3054 https://doi.org/10.64388/IREV10I1-1720191
Darshankumar Jaysukh Dhanani "AI-Powered Cyber Threat Detection and Automated Incident Response" Iconic Research And Engineering Journals, vol. 10, no. 1, Jul. 2026, doi: https://doi.org/10.64388/IREV10I1-1720191
Darshankumar Jaysukh Dhanani (2026). AI-Powered Cyber Threat Detection and Automated Incident Response. Iconic Research And Engineering Journals, 10(1). doi: https://doi.org/10.64388/IREV10I1-1720191
Darshankumar Jaysukh Dhanani "AI-Powered Cyber Threat Detection and Automated Incident Response" Iconic Research And Engineering Journals, vol. 10, no. 1, Jul. 2026. Crossref, https://doi.org/10.64388/IREV10I1-1720191
@article{1720191,
      author = {Darshankumar Jaysukh Dhanani},
      title = {AI-Powered Cyber Threat Detection and Automated Incident Response},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {10},
      number = {1},
      pages = {3043-3054},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1720191.pdf},
      abstract = {As the volume, speed and sophistication of cyberattacks continue to increase, the ability of traditional signature-based and manually-operated security controls has not kept up, which is leading to the broad use of artificial intelligence (AI) throughout the cybersecurity lifecycle. This paper summarizes the latest advances in intrusion detection, explainable AI, ransomware and phishing detection, and security orchestration, automation, and response (SOAR) platforms and their role in cyber threat detection and automated incident response. The methodology employed in this literature review was narrative because it enabled identification and synthesis of peer-reviewed literature and authoritative technical standards of machine learning, deep learning and agentic artificial intelligence applications in security operations. The review concludes that AI-based detection systems consistently beat traditional rule-based detection systems on both reported accuracy and false positive metrics, explainability is emerging as a central requirement to enable analysts to build trust in the technology and to ensure regulatory compliance, and automation of incident response, especially with SOAR and new agentic architectures, significantly lowers mean time to containment and analyst workload. Meanwhile, the review outlines ongoing challenges such as combating adversarial use of AI models, addressing data quality issues, handling the complexity of integrating AI systems, and the ongoing need for human oversight. The paper argues that the auto-D&A should be used as an asset to augment human security analysts and not supplant them, and provides tips for companies looking to implement these technologies in responsible ways.},
      keywords = {Artificial Intelligence, Cyber Threat Detection, Automated Incident Response, Machine Learning, Security Orchestration, Explainable AI},
      month = {July},
      doi = {https://doi.org/10.64388/IREV10I1-1720191}
  }