{"id":"https://openalex.org/W4413556821","doi":"https://doi.org/10.1109/access.2025.3602681","title":"A Multi-Agent System for Cybersecurity Threat Detection and Correlation Using Large Language Models","display_name":"A Multi-Agent System for Cybersecurity Threat Detection and Correlation Using Large Language Models","publication_year":2025,"publication_date":"2025-01-01","ids":{"openalex":"https://openalex.org/W4413556821","doi":"https://doi.org/10.1109/access.2025.3602681"},"language":"en","primary_location":{"id":"doi:10.1109/access.2025.3602681","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2025.3602681","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1109/access.2025.3602681","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5119419915","display_name":"Yasser Hmimou","orcid":null},"institutions":[{"id":"https://openalex.org/I4210121440","display_name":"Moroccan Foundation for Advanced Science, Innovation and Research","ror":"https://ror.org/02gjqpv16","country_code":"MA","type":"nonprofit","lineage":["https://openalex.org/I4210121440"]}],"countries":["MA"],"is_corresponding":false,"raw_author_name":"Yasser Hmimou","raw_affiliation_strings":["Multidisciplinary Laboratory of Research and Innovation (LPRI), Moroccan School of Engineering Sciences (EMSI), Casablanca, Morocco"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Multidisciplinary Laboratory of Research and Innovation (LPRI), Moroccan School of Engineering Sciences (EMSI), Casablanca, Morocco","institution_ids":["https://openalex.org/I4210121440"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5015679036","display_name":"Mohamed Tabaa","orcid":"https://orcid.org/0000-0003-3938-3566"},"institutions":[{"id":"https://openalex.org/I4210121440","display_name":"Moroccan Foundation for Advanced Science, Innovation and Research","ror":"https://ror.org/02gjqpv16","country_code":"MA","type":"nonprofit","lineage":["https://openalex.org/I4210121440"]}],"countries":["MA"],"is_corresponding":false,"raw_author_name":"Mohamed Tabaa","raw_affiliation_strings":["Multidisciplinary Laboratory of Research and Innovation (LPRI), Moroccan School of Engineering Sciences (EMSI), Casablanca, Morocco"],"raw_orcid":"https://orcid.org/0000-0003-3938-3566","affiliations":[{"raw_affiliation_string":"Multidisciplinary Laboratory of Research and Innovation (LPRI), Moroccan School of Engineering Sciences (EMSI), Casablanca, Morocco","institution_ids":["https://openalex.org/I4210121440"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5023307048","display_name":"Azeddine Khiat","orcid":"https://orcid.org/0000-0002-7090-9098"},"institutions":[{"id":"https://openalex.org/I99297268","display_name":"University of Hassan II Casablanca","ror":"https://ror.org/001q4kn48","country_code":"MA","type":"education","lineage":["https://openalex.org/I99297268"]}],"countries":["MA"],"is_corresponding":false,"raw_author_name":"Azeddine Khiat","raw_affiliation_strings":["2IACS Laboratory, ENSET, Hassan II University of Casablanca, Casablanca, Morocco","2IACS Laboratory, ENSET, Hassan II University, Casablanca, Morocco"],"raw_orcid":"https://orcid.org/0000-0002-7090-9098","affiliations":[{"raw_affiliation_string":"2IACS Laboratory, ENSET, Hassan II University of Casablanca, Casablanca, Morocco","institution_ids":["https://openalex.org/I99297268"]},{"raw_affiliation_string":"2IACS Laboratory, ENSET, Hassan II University, Casablanca, Morocco","institution_ids":["https://openalex.org/I99297268"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5055285480","display_name":"Zineb Hidila","orcid":"https://orcid.org/0000-0003-1104-4896"},"institutions":[{"id":"https://openalex.org/I4210121440","display_name":"Moroccan Foundation for Advanced Science, Innovation and Research","ror":"https://ror.org/02gjqpv16","country_code":"MA","type":"nonprofit","lineage":["https://openalex.org/I4210121440"]}],"countries":["MA"],"is_corresponding":false,"raw_author_name":"Zineb Hidila","raw_affiliation_strings":["Multidisciplinary Laboratory of Research and Innovation (LPRI), Moroccan School of Engineering Sciences (EMSI), Casablanca, Morocco"],"raw_orcid":"https://orcid.org/0000-0003-1104-4896","affiliations":[{"raw_affiliation_string":"Multidisciplinary Laboratory of Research and Innovation (LPRI), Moroccan School of Engineering Sciences (EMSI), Casablanca, Morocco","institution_ids":["https://openalex.org/I4210121440"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":{"value":1850,"currency":"USD","value_usd":1850},"apc_paid":{"value":1850,"currency":"USD","value_usd":1850},"fwci":5.3207,"has_fulltext":false,"cited_by_count":5,"citation_normalized_percentile":{"value":0.95874838,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":"13","issue":null,"first_page":"150199","last_page":"150215"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.786300003528595,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.786300003528595,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.7824000120162964,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.7576000094413757,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.759885847568512},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.74289870262146}],"concepts":[{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.759885847568512},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.74289870262146}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/access.2025.3602681","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2025.3602681","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:400730d3d91a4da1a1190b014fdfd9ee","is_oa":true,"landing_page_url":"https://doaj.org/article/400730d3d91a4da1a1190b014fdfd9ee","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Access, Vol 13, Pp 150199-150215 (2025)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1109/access.2025.3602681","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2025.3602681","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":44,"referenced_works":["https://openalex.org/W4223503494","https://openalex.org/W4226128225","https://openalex.org/W4328028653","https://openalex.org/W4372260394","https://openalex.org/W4376288669","https://openalex.org/W4387653636","https://openalex.org/W4391592188","https://openalex.org/W4392353733","https://openalex.org/W4392821836","https://openalex.org/W4393150198","https://openalex.org/W4396558173","https://openalex.org/W4398239377","https://openalex.org/W4399625707","https://openalex.org/W4400915556","https://openalex.org/W4401004521","https://openalex.org/W4401357555","https://openalex.org/W4402892453","https://openalex.org/W4403007355","https://openalex.org/W4403211967","https://openalex.org/W4403295895","https://openalex.org/W4403329963","https://openalex.org/W4403600666","https://openalex.org/W4403835869","https://openalex.org/W4404688214","https://openalex.org/W4404817466","https://openalex.org/W4405022259","https://openalex.org/W4405460579","https://openalex.org/W4406461453","https://openalex.org/W4406842332","https://openalex.org/W4406928793","https://openalex.org/W4407163436","https://openalex.org/W4407208713","https://openalex.org/W4407786437","https://openalex.org/W4408167800","https://openalex.org/W4408656758","https://openalex.org/W4408859326","https://openalex.org/W4409140393","https://openalex.org/W4409676367","https://openalex.org/W4409965620","https://openalex.org/W4409965657","https://openalex.org/W4409966583","https://openalex.org/W4410087115","https://openalex.org/W4410140821","https://openalex.org/W4411207733"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052"],"abstract_inverted_index":{"As":[0],"cyber-attacks":[1],"rapidly":[2],"evolve":[3],"across":[4,145],"communication,":[5],"infrastructure":[6],"and":[7,37,55,65,85,94,106,139,158,174,182,202,238,254,272,279],"data":[8,147],"layers,":[9],"traditional":[10,110,262],"security":[11],"solutions":[12],"such":[13,215],"as":[14,101,216],"rule-based":[15],"intrusion":[16],"detection":[17,60,96,142,168,227,245],"systems":[18,84,111],"(IDS)":[19],"or":[20,44,77,114,219],"signature-based":[21],"antivirus":[22],"programs":[23],"are":[24],"effective":[25],"at":[26],"detecting":[27,75],"known":[28],"threats,":[29],"but":[30],"they":[31],"often":[32,58],"lack":[33],"the":[34,190,193,204],"contextual":[35,197],"understanding":[36],"semantic":[38,90,176],"interpretation":[39],"necessary":[40],"to":[41,62,135,179,186,210,261],"detect":[42,211],"complex":[43,212],"evolving":[45],"attacks.":[46],"For":[47],"example,":[48],"spear-phishing":[49],"campaigns,":[50],"advanced":[51],"persistent":[52],"threats":[53,144,184],"(APTs),":[54],"multi-stage":[56],"attacks":[57,221],"escape":[59],"due":[61],"their":[63,187],"subtle":[64,78],"context-dependent":[66],"nature.":[67],"This":[68,117],"limitation":[69],"creates":[70],"a":[71,120,196],"critical":[72],"gap":[73],"in":[74],"coordinated":[76],"attack":[79],"patterns":[80,214],"that":[81,109,124,170,200,222],"span":[82],"multiple":[83],"domains.":[86],"The":[87,229,264],"need":[88],"for":[89,268],"understanding,":[91],"cross-domain":[92],"visibility,":[93],"adaptive":[95],"is":[97],"increasingly":[98],"urgent,":[99],"particularly":[100],"threat":[102,213,244],"actors":[103],"employ":[104],"polymorphic":[105],"AI-driven":[107],"strategies":[108],"cannot":[112],"interpret":[113],"correlate":[115],"effectively.":[116],"paper":[118],"presents":[119],"modular":[121],"multi-agent":[122,249],"architecture":[123],"integrates":[125],"established":[126],"cybersecurity":[127],"analysis":[128,177],"tools":[129,173],"with":[130,166],"large":[131],"language":[132],"models":[133],"(LLMs)":[134],"achieve":[136],"intelligent,":[137],"explicable":[138],"highly":[140],"accurate":[141],"of":[143,192,206,247,252,258,266],"diverse":[146],"types.":[148],"Three":[149],"specialized":[150,208],"agents:":[151],"(1)":[152],"email":[153],"verification,":[154],"(2)":[155],"log":[156],"analysis,":[157],"(3)":[159],"IP":[160],"address":[161],"scanning":[162],"each":[163],"operate":[164],"independently":[165],"tailored":[167],"pipelines":[169],"combine":[171],"domain-specific":[172],"LLM-powered":[175],"components":[178],"identify,":[180],"characterize,":[181],"report":[183],"specific":[185],"domain.":[188],"At":[189],"core":[191],"system":[194,199],"lies":[195],"recommendation":[198],"processes":[201],"cross-analyzes":[203],"outputs":[205],"all":[207],"agents":[209],"multi-vector,":[217],"time-based,":[218],"stealth":[220],"would":[223],"otherwise":[224],"evade":[225],"isolated":[226],"mechanisms.":[228],"evaluation":[230],"on":[231],"benchmark":[232],"datasets,":[233],"including":[234],"CIC-IDS":[235],"2017,":[236],"SpamAssassin,":[237],"custom":[239],"simulated":[240],"network":[241],"environments,":[242],"demonstrates":[243],"accuracy":[246,251],"93.6%,":[248],"correlation":[250],"87%,":[253],"false":[255],"positive":[256],"reduction":[257],"41.3%":[259],"compared":[260],"approaches.":[263],"use":[265],"LLMs":[267],"both":[269],"structured":[270],"explanations":[271],"chain-of-thought":[273],"reporting":[274],"further":[275],"enhances":[276],"analyst":[277],"confidence":[278],"reduces":[280],"triage":[281],"time.":[282]},"counts_by_year":[{"year":2026,"cited_by_count":5}],"updated_date":"2026-06-19T17:40:00.097472","created_date":"2025-10-10T00:00:00"}
