Loading...

GreenShieldX: SOC AI-native per una cybersecurity

GreenShieldX sviluppa una nuova generazione di SOC basata su IA, automazione e spiegabilità delle decisioni.

GreenShieldX
  • Cybersecurity

GreenShieldX is a Research and Development project promoted by Mashfrog Group to create a platform and a new Security Operations Center service line based on a platform + service model. Its objective is to develop an AI-native SOC capable of supporting threat detection and correlation, response orchestration and analyst activities through decisions that are easier to understand, verify and trace.


The project addresses the security operations lifecycle as an integrated process. Signals generated by monitored systems are analysed through artificial-intelligence models and semantic-correlation mechanisms to reconstruct relationships between events, assets and potentially anomalous behaviours, providing the SOC with richer context than the management of isolated alerts alone.


A central part of the research focuses on advanced model families, including Graph Neural Networks, LSTM architectures and Transformers, combined with Knowledge Graphs and semantic-representation techniques. These approaches are investigated to improve the ability to identify complex patterns and connect information distributed across different sources.


GreenShieldX extends automation to incident response. Orchestration is designed to reduce repetitive manual activities and shorten the time between threat identification and action, while keeping analysts involved in steps that require validation, risk assessment or explicit authorisation.


Explainability is treated as an operational requirement. In a Security Operations Center, producing a technically correct model output is not enough: analysts, security managers and compliance functions must be able to reconstruct the evidence and reasoning behind a classification or recommendation. For this reason, the project develops an Explainable AI and Knowledge Interface layer designed to make AI-supported decisions more verifiable.


Alongside security performance, the project addresses the computational efficiency of AI models. Frugal AI techniques such as pruning, quantisation and distillation are investigated together with performance-per-watt and carbon-footprint metrics, with the objective of reducing resource consumption without treating this dimension as separate from the overall platform design.

Seven development areas for an AI-native SOC

GreenShieldX is organised into seven workstreams that lead from architectural design to end-to-end validation of the solution:

 

1- Hybrid Cloud-HPC architecture and MLOps framework

An architecture designed to support compute-intensive AI workloads and flexibly distribute training, inference and application services. The MLOps framework governs the model lifecycle, experiment reproducibility, deployment and monitoring of model versions in operation.

 

2- Cognitive Threat Detection

A detection engine that applies AI models to the correlation of security events and signals. The objective is to improve the ability to distinguish relevant phenomena from operational noise and build a more contextualised representation of threats.

 

3- Incident-response orchestration

A set of mechanisms for coordinating post-detection actions in a more automated way, reducing response times and repetitive manual work. The most critical decisions remain within a human-in-the-loop operating model.

 

4- Explainable AI and Knowledge Interface

A layer dedicated to the explanation and traceability of decisions supported by artificial intelligence. Technical evidence, semantic relationships and operational context are organised to provide views aligned with the needs of SOC analysts, CISOs and compliance functions.

 

5- Energy-aware deployment and optimisation

A component focused on the efficiency of AI workloads, using techniques such as pruning, quantisation and distillation together with energy metrics. The objective is to assess performance, computational consumption and infrastructure sustainability within the same design framework.

Adversarial resilience and AI security hardening

A workstream focused on the security of the AI components themselves, considering threats such as evasion, poisoning and prompt injection. The activities are intended to improve the robustness of models and AI-enabled services against deliberate manipulation and anomalous behaviour.


Integration and validation in a SOC-like environment
The final phase integrates architecture, detection models, orchestration, explainability, MLOps and energy optimisation into an end-to-end prototype. Validation is carried out in an environment representative of SOC operations to verify the interaction between components and move the solution towards a pre-operational configuration.