BoryShield Platform | Bory AI Cybersecurity Analytics Platform |
A cybersecurity AI platform that analyzes security logs and threat data with AI and connects them to explainable evidence and report automation
BoryShield Platform is Bory's AI cybersecurity analytics platform that analyzes security logs, breach events, threat intelligence, security policy documents, response histories, and past incident reports with AI to understand cyber threats and connect the results to analytical evidence and report automation.
Corporate and institutional security environments generate diverse security data, including firewall, EDR, IDS/IPS, WAF, SIEM, server, cloud, network equipment, and user behavior logs. However, the volume is high, formats are complex, and personnel often lack the time and resources to analyze every event manually and organize the findings into reports.
BoryShield Platform organizes this security data into a structure that AI can understand and provides LLM-based summarization, explainable AI analysis, internal security document search, threat event classification, incident flow analysis, response action recommendations, and draft report generation as a common platform.
BoryShield Platform can be deployed as a standalone platform or integrated with BoryShield XAI Solution, BoryForesight Platform, BoryData Platform, security monitoring systems, internal document systems, and customers' existing security systems such as SIEM, EDR, and WAF.
[Platform Adoption Inquiry] [AI Security Analytics Platform Consultation] [Security Report Automation PoC Inquiry] [Request a Proposal]

Platform Definition
BoryShield Platform is a common platform that modularizes Bory's AI cybersecurity analytics technologies.
A product is a package delivered to a customer, a solution is a system built for the customer's environment, and a platform is a common technology foundation for repeatedly creating multiple products and solutions.
BoryShield Platform provides the following capabilities within a unified platform architecture.
- Security log collection and normalization
- Integrated security event search
- LLM-based security event summarization
- Explainable AI analysis
- Provision of grounds for threat assessments
- Attack flow analysis
- Assistance with incident root-cause analysis
- Response action recommendations
- Security report automation
- Internal security document search
- Threat intelligence integration
- Security dashboard configuration
- SIEM, EDR, WAF, and firewall log integration
- Support for on-premises, closed-network, and cloud deployment
In other words, BoryShield Platform is Bory's common AI cybersecurity analytics platform that “collects, connects, understands, explains, and converts security data into reports.”
Customer Challenges
There are too many security events for personnel to analyze them all
Companies and institutions generate countless security events every day.
Firewall block logs, EDR detection events, IDS/IPS alerts, WAF detection logs, server access records, cloud security events, and user behavior logs continue to accumulate, making it difficult for people to review every event manually.
BoryShield Platform uses AI to summarize security events and organize their risk levels and related events, enabling security personnel to prioritize the most important events.
Security data is scattered across multiple systems
Security logs and events are often separated by device, system, and department.
Even logs related to the same incident may be divided across firewalls, servers, EDR, SIEM, and internal documents, making it difficult for personnel to understand the incident flow.
BoryShield Platform provides a common structure for integrated searches across diverse security data and internal documents and for connecting and analyzing related events.
It is difficult to explain the grounds for threat assessments
Evidence is required to determine whether a security event is an actual attack, a simple alert, or a false positive.
Reports and internal meetings must explain “why it is dangerous,” “which logs provide the evidence,” “which systems were affected,” and “what actions are required.”
Through an explainable AI analysis architecture, BoryShield Platform helps present the grounds for threat assessments, related logs, attack flows, and the need for response measures together.
Security report preparation is a recurring task
Security personnel must repeatedly prepare daily monitoring reports, weekly security reports, incident analysis reports, customer reports, executive summary reports, and recurrence prevention action reports.
BoryShield Platform automatically organizes analysis results into draft reports and provides a report automation structure that personnel can review, edit, and approve.
Knowledge from past incidents and internal security documents is not being fully utilized
Even when past incident reports, response manuals, security policies, detection rules, and vulnerability remediation documents are available, personnel often cannot find them quickly when needed.
BoryShield Platform converts internal security documents into searchable knowledge assets so that past cases and internal standards can be used together when analyzing new events.
Platform Overview
BoryShield Platform is an AI security analytics platform that analyzes, searches, summarizes, and reports on cybersecurity data.
The main components are as follows.
- Security log input module
- Event normalization module
- Integrated log and document search module
- LLM-based summarization module
- XAI analytical evidence module
- Threat event classification module
- Attack flow timeline module
- Incident root-cause analysis assistance module
- Response action recommendation module
- Report automation module
- Security dashboard
- Internal security document search module
- User authorization and security management module
- External security system API integration module
BoryShield Platform can be configured for on-premises, closed-network, cloud, or API-integrated deployment according to the customer's security environment.
Core Modules
1. Security Log Collection and Normalization Module
This module collects data generated by firewalls, EDR, IDS/IPS, WAF, SIEM, servers, cloud systems, network equipment, and user behavior logs and organizes it into an analyzable format.
It converts device-specific log formats into a common analytical structure that can be used for event searches, summarization, risk analysis, and report automation.
Examples of use include the following.
- Firewall log organization
- EDR detection event organization
- WAF attack detection log organization
- Server access record analysis
- Cloud security event collection
- SIEM event integration
2. Integrated Security Event Search Module
This module provides integrated searches across security logs, events, past incident reports, response manuals, and security policy documents scattered across multiple systems.
Security personnel can quickly find relevant information based on a specific IP address, account, asset, event type, attack technique, incident number, or vulnerability keyword.
Examples of use include the following.
- IP-based related log search
- Account-based anomalous behavior search
- Event lookup by asset
- Past incident report search
- Detection rule document search
- Internal response manual search
3. LLM-Based Security Event Summarization Module
This module summarizes complex security events and log contents in language that people can easily understand.
Rather than displaying lengthy logs as-is, it organizes the information around occurrence time, related assets, suspicious behavior, scope of impact, and items requiring verification.
Examples of use include the following.
- Key security event summary
- Potential incident event summary
- Summary of related log groups
- Summary for management reporting
- Summary for customer delivery
- Organization of items requiring personnel review
4. Explainable AI Analysis Module
This module presents the grounds for the analytical results provided by AI.
Rather than simply labeling an event as “dangerous,” it is designed to explain which logs and behaviors served as the basis for the risk assessment.
Examples of use include the following.
- Display of grounds for threat assessments
- Display of related log sources
- Linking to supporting detection rules
- Linking to similar past incidents
- Assistance with reviewing the possibility of false positives
- Explanation of the need for response measures
5. Threat Event Classification Module
This module classifies security events by type and organizes their priorities.
Based on event severity, frequency, scope of impact, asset importance, likelihood of attack, and similar past cases, it distinguishes the items that personnel should review first.
Examples of use include the following.
- Classification of critical events
- Classification of potential false positives
- Classification of anomalous account behavior
- Classification of suspected external attacks
- Classification of suspected lateral movement
- Risk classification based on asset importance
6. Attack Flow Timeline Module
This module connects multiple events chronologically and organizes the attack flow.
It places suspicious abnormal logins, privilege escalation, lateral movement, file access, external communications, and malicious behavior events on a timeline so that personnel can quickly understand the incident flow.
Examples of use include the following.
- Organization of events by attack stage
- Generation of a security incident timeline
- Account-centric behavior flow analysis
- Asset-centric event flow analysis
- Organization of suspected lateral movement flows
- Organization of external communication flows
7. Incident Root-Cause Analysis Assistance Module
When a security incident occurs, this module organizes potential causes and items requiring verification based on related logs and events.
AI does not make the final decision; instead, it structures the relevant data so that personnel can rapidly review the cause of the incident.
Examples of use include the following.
- Organization of potential incident causes
- Organization of affected systems
- Organization of related accounts, IP addresses, and assets
- Suggestions for additional logs to review
- Organization of potential recurrence prevention measures
- Generation of an internal root-cause analysis draft
8. Response Action Recommendation Module
This module proposes a checklist of actions that personnel should review according to the security event type and internal response criteria.
It can be configured as a customer-specific action process that reflects the organization's security policies, response manuals, and past incident handling standards.
Examples of use include the following.
- Review of account lockout
- Password change request
- Review of system isolation
- Request for malicious file analysis
- Review of firewall blocking policies
- Request for additional log review
- Guidance on personnel reporting procedures
- Organization of recurrence prevention measures
9. Security Report Automation Module
This module automatically organizes analysis results according to the customer's report format.
Security personnel can review and edit AI-generated draft reports and then use them as internal or customer-facing reports.
The following reports can be generated.
- Security incident analysis report
- Security event analysis report
- Daily security monitoring report
- Weekly security report
- Customer response report
- Recurrence prevention action report
- Executive summary report
- Audit response reference report
10. Security Dashboard Module
This module visualizes security event status, risk distribution, processing status, recurring events, report generation status, and risk status by asset.
Depending on the organization's security operations, it can be configured as a SOC dashboard, internal analysis screen, report review screen, or administrator screen.
Examples of use include the following.
- Event occurrence status
- Distribution by risk level
- Processing status by assignee
- Risk status by asset
- Report generation status
- Recurring event statistics
- Security status by customer
- Monthly and weekly report status
Platform Deployment Models
On-Premises
Organizations with restricted external network access, such as companies, public institutions, financial institutions, and security operations centers, can deploy the platform on internal servers.
It is suitable for organizations that cannot easily transmit security logs and internal documents externally.
Closed Network
Platform deployment can also be considered in closed-network environments where internet access is restricted by security policy.
The LLM model, document search, and report automation capabilities are designed for operation within the internal network without external transmission.
Cloud
When multiple customers or branches need to be managed centrally, the platform can be configured as a cloud-based security analytics platform.
It is suitable for managed security service providers and organizations that manage multiple customers.
API Integration
The platform can integrate through APIs with the customer's existing SIEM, EDR, WAF, firewalls, log servers, ticketing systems, and document management systems.
This approach retains existing security systems while adding AI analysis, summarization, and report automation capabilities.
Application Areas
Security Operations Center
AI summarizes large volumes of security events and helps personnel prioritize high-risk events.
Monitoring personnel can quickly review the core event details, related logs, risk level, and potential response actions.
Internal Corporate Security Team
Internal corporate security teams can use BoryShield Platform to streamline security event analysis, incident response, internal reporting, security document search, and response manual review.
Public-Sector Security Operations
Public institutions can use the platform in internal or closed networks for security event analysis, incident report preparation, organization of audit response materials, and security policy document searches.
Managed Security Service Provider
Security service providers can use the platform for customer-specific security event analysis, weekly and monthly report preparation, and incident response report automation.
Customer-specific report templates and analysis criteria can be incorporated into the platform.
Security Incident Analysis
When a security incident occurs, the platform can connect related logs and organize the incident flow, potential causes, scope of impact, and draft response actions.
Personnel can use the AI analysis results as a reference when making final decisions and preparing reports.
Security Training and Work Standardization
The platform can be used to train new security personnel, standardize monitoring work, apply response manuals, and study past incident cases.
Systematizing analytical evidence and response procedures can help reduce differences among personnel.
Integrated Products and Solutions
BoryShield XAI
It serves as the core AI analytics platform for the LLM-based XAI cyber threat analysis package.
It provides security event summarization, threat analysis, and report automation capabilities.
BoryShield XAI Solution
It serves as the foundational platform for a cyber threat analysis and report automation solution built around the customer's security logs, internal security documents, and report formats.
BoryForesight Platform
It can be extended into security incident prediction and analysis by linking with incident cause prediction, risk situation analysis, and XAI-based integrated monitoring architectures.
BoryData Platform
It can integrate as a data-driven platform for analyzing and processing security logs, event data, report data, and operational statistics.
BORY AI Platform
LLM, XAI, data analytics, document search, and report automation capabilities can be connected from the perspective of a common AI platform.
Expected Benefits
Improved Security Analysis Efficiency
AI can summarize security events and connect related logs, reducing the time required for initial analysis by personnel.
Clearer Grounds for Threat Assessments
By presenting risk levels, related logs, attack flows, and the need for response measures together, the platform can improve the explainability of security analysis results.
Security report automation
It can reduce the burden of document preparation by automating recurring security monitoring reports, incident reports, and customer reports.
Improved Utilization of Internal Security Knowledge
Past incident reports, response manuals, security policies, and detection rule documents can be converted into searchable knowledge assets.
Enhancement of Existing Security Systems
Rather than replacing existing SIEM, EDR, WAF, firewalls, and log systems, the platform can add AI analysis, summarization, and report automation capabilities on top of them.
Standardization of Security Operations Quality
It can reduce differences in personnel experience and standardize security operations quality by incorporating the organization's response criteria and report formats into the platform.
Implementation Process
1. Requirements Review
Review the customer's security operations, log collection architecture, systems to be analyzed, report formats, internal security policies, and deployment environment.
2. Data Structure Analysis
Analyze the structures of security logs, event data, past reports, detection rules, response manuals, asset information, and threat intelligence data.
3. Platform Architecture Design
Design the scope of log collection, event search, LLM summarization, XAI analysis, report automation, dashboards, authorization management, and API integration.
4. PoC Implementation
Using selected log data and past reports, validate event summarization, presentation of analytical evidence, automatic report generation, and internal search capabilities.
5. Platform Implementation
Build an AI analytics engine, document search architecture, database, dashboard, report automation modules, and user authorization architecture suited to the customer's environment.
6. Security System Integration
Integrate with SIEM, EDR, WAF, firewalls, log servers, internal document systems, ticketing systems, and report management systems.
7. Operational Validation and Enhancement
Using actual security operations data, improve analysis quality, report quality, risk criteria, response checklists, and personnel review processes.
What BoryShield Platform Can Do
- Build an AI cybersecurity analytics platform
- Security log collection and normalization
- Integrated security event search
- LLM-based security event summarization
- Provide explainable AI analytical evidence
- Classify threat events
- Generate attack flow timelines
- Assistance with incident root-cause analysis
- Generate response action checklists
- Automate security incident analysis reports
- Automate daily and weekly security monitoring reports
- Build an internal security document search system
- Search and utilize past incident reports
- SIEM, EDR, WAF, and firewall log integration
- Build a security operations dashboard
- Build an on-premises security AI platform
- Build a closed-network security analytics platform
- Build a cloud-based security analytics platform
- Integrate the core platform with BoryShield XAI Solution
Adoption Inquiry
Depending on the customer's security data architecture, security equipment configuration, report formats, internal security policies, and deployment environment, BoryShield Platform can be proposed as an on-premises, closed-network, cloud, API-integrated, security operations center, or report automation model.
- AI Cybersecurity Analytics Platform Adoption Inquiry
- LLM-Based Security Event Analytics Platform Inquiry
- Integrated Security Log Search Platform Inquiry
- Security Incident Analysis Report Automation Inquiry
- Security Monitoring Report Automation Inquiry
- Internal Security Document Search System Inquiry
- SIEM, EDR, and WAF Log Integration Inquiry
- Security Dashboard Implementation Inquiry
- On-Premises Security AI Platform Inquiry
- Closed-Network Security Analytics Platform Inquiry
- BoryShield XAI Solution Integration Inquiry
- Request a PoC Proposal
Important Information
BoryShield Platform is an AI-based cybersecurity analytics platform that supports security event analysis, threat summarization, incident root-cause analysis assistance, report automation, and internal security document search.
This platform assists security personnel with analysis and response work and does not guarantee automatic detection of every cyber threat or complete prevention of every security incident.
AI analysis results, risk classifications, response action recommendations, and draft reports must be reviewed by security personnel and finalized in accordance with the organization's security policies.
When security logs, incident information, internal documents, asset information, or customer information are stored or analyzed, information protection policies, access permissions, encryption, log management, and internal security standards must be agreed upon in advance.
When applying LLM-based report automation, we recommend jointly designing source log references, personnel review, approval procedures, prohibited-term management, and external transmission restrictions to reduce the risk of fabricated information.
When integrating external threat intelligence, security equipment, SIEM, EDR, WAF, firewalls, or internal document systems, the implementation scope may vary depending on API availability, data formats, security policies, and network architecture.
Before adoption, the analysis objectives, scope of log integration, report formats, data retention criteria, security policies, user permissions, and operational processes must be reviewed.
Related Products, Solutions, and Platforms
Related Products
- BoryShield XAI / Bory LLM-Based XAI Cyber Threat Analysis Package
Related Solutions
- BoryShield XAI Solution / Bory LLM-Based Cyber Threat Analysis and Report Automation Solution
- BoryForesight Solution / Bory XAI Integrated Monitoring Solution for Incident Cause Prediction
- BoryData Solution / Bory Data Analytics and Processing Solution
- BoryTalk Solution / Bory AI Chatbot and Consultation Automation Solution
Related Platforms
- BoryForesight Platform / Bory XAI Integrated Monitoring Platform for Incident Cause Prediction
- BoryData Platform / Bory Data Analytics Platform
- BORY AI Platform / Bory Artificial Intelligence Platform
BORY.ai Key Services Overview
Bory Co., Ltd. develops products, solutions, platforms, and services for industrial, medical, public-sector, healthcare, and barrier-free applications based on AI technologies involving speech, language, video, sensors, and data.
Below are the main representative domains currently operated or being prepared by Bory Co., Ltd.
| Primary Domain | Service/Brand | Description |
| bory.ai | BORY.ai | The official AI brand website of Bory Co., Ltd., serving as the company’s main website for the integrated presentation of its products, solutions, platforms, and services |
| borysense.com | BORY SENSE | An AI-powered hearing assistance platform that supports communication for people with hearing disabilities and older adults through real-time captioning, lip-reading AI, and AR glasses integration |
| borytalk.com | BORY TALK | A web-based conversational AI chatbot service designed for civil service inquiries, consultations, information guidance, and customer support |
| borykiosk.com | BORY KIOSK | A barrier-free AI kiosk service for older adults and people with disabilities, featuring voice guidance, captioning, and easy-to-use interfaces |
| boryservice.com | BORY SERVICE | A service portal introducing Bory’s AI services and custom-built AI offerings for industrial, public-sector, and everyday applications |
| borysong.com | BORY SONG | A music AI service that supports AI-powered composition, music generation, and sound content production |
'English > Platform(플랫폼)' 카테고리의 다른 글
| BORY AI Platform (0) | 2026.08.05 |
|---|---|
| BoryForesight Platform (0) | 2026.08.04 |
| BoryLifeSafe Platform (0) | 2026.08.04 |
| BorySafe Platform (0) | 2026.08.04 |
| BoryKiosk Platform (0) | 2026.08.04 |





최근댓글