BoryShield XAI Solution | BORY LLM-Based Cyber Threat Analysis and Report Automation Solution
An LLM-based XAI security analysis solution that analyzes security logs and threat detection results and automatically organizes detection evidence and response information into reports
BoryShield XAI Solution is an LLM-based cyber threat analysis and report automation solution that analyzes security logs, threat detection results, network events, and threat intelligence data generated by enterprises, public institutions, and security operations organizations, and automatically organizes them into explanatory reports that security personnel can understand.
Existing security operations systems detect threat events and provide alerts, but security personnel must still reinterpret the detection results, review related logs, find similar past cases, and compile reports. This process is repetitive and time-consuming, and the quality of analysis may vary depending on the analyst's experience.
BoryShield XAI Solution enhances security analysis by combining vector-based similarity search, keyword search, LLM-based threat explanations, and automated XAI report generation for security data.
It can be integrated with a customer's existing SIEM, security operations system, log collection system, and threat detection system to automate cyber threat analysis and report preparation.
[Solution Adoption Inquiry][Security Report Automation Consultation][PoC Implementation Inquiry][Request a Proposal]

Customer Challenges
There are many security events, but not enough time to analyze them
Corporate and institutional security systems generate large volumes of logs and events every day. However, it is difficult for people to manually analyze every event and document whether it is a threat and the basis for that judgment.
BoryShield XAI Solution analyzes the threat context based on detection results and automatically generates explanatory reports for review, reducing security analysis time.
It is difficult to explain the basis for detection results
Even when security equipment detects a threat event, a separate process is required to explain why the event is dangerous, which logs support the judgment, and which past cases are similar.
BoryShield XAI Solution analyzes detection results and related data and organizes the threat assessment basis, key indicators, similar cases, and response reference information into a natural-language report.
Report-writing tasks occur repeatedly
Security operations work requires various types of documents, including customer reports, internal reports, incident response reports, and audit response reports.
BoryShield XAI Solution supports the configuration of report templates according to each institution's report format and analysis items, enabling automatic documentation of threat event analysis results.
It is difficult to quickly find emerging threats and similar cases
Emerging or modified attacks may be difficult to find through conventional keyword searches alone.
BoryShield XAI Solution vectorizes security data and applies similarity search to help find threat cases that are expressed differently but are semantically similar.
Solution Overview
BoryShield XAI Solution integrates security logs, detection events, threat intelligence, past incident cases, and analysis report data to provide analysis results in a form that security personnel can understand.
Key functions include the following.
- Collection of security logs and detection results
- Threat data preprocessing
- Security data vectorization
- Keyword and similarity search
- Search for similar past threat cases
- LLM-based threat explanation generation
- Automated XAI report generation
- Report template management
- Administrator analysis interface implementation
- Integration with existing security operations systems
- API-based delivery of analysis results
Key Functions
1. Security Log and Detection Result Analysis
BoryShield XAI Solution can analyze event data generated by security equipment, monitoring systems, and log collection systems.
Depending on the customer's environment, it can integrate various security data such as firewalls, EDR, NDR, IDS/IPS, SIEM, web application firewalls, server logs, and network logs.
The data to be analyzed is adjusted according to the customer's security environment and the scope of integration.
2. Vector-Based Similarity Search
Security logs, attack descriptions, detection results, and threat intelligence data can be vectorized to search for similar threat cases.
Even when ordinary keywords do not match exactly, it can be used to find semantically similar attack patterns, past cases, and analysis reports.
This enables security personnel to identify more quickly how a new event relates to existing attack types.
3. Keyword Search and Hybrid Search
Accurate indicator searches are also important in security analysis.
BoryShield XAI Solution can use explicit keyword searches for IP addresses, domains, hashes, attack names, vulnerability names, device names, log fields, and more together with semantic vector searches.
This enables a security analysis environment that combines precise searches with searches for similar cases.
4. LLM-Based Threat Explanation Generation
Based on detected events, BoryShield XAI Solution can organize the threat type, key indicators, basis for judgment, similar cases, and response references in natural language.
Before interpreting complex logs and event data, security personnel can first review AI-generated summaries and explanations.
5. Automated XAI Report Generation
Threat detection results can be automatically organized in report form.
Reports may include the following information.
- Detection event summary
- Threat type
- Key logs and indicators
- Basis for judgment
- Similar threat cases
- Reference information for risk assessment
- Recommended response actions
- Analyst review notes
- Institution-specific report format
Templates can be adjusted to match the customer's internal reporting format or security operations report format.
6. Report Template Management
Each institution has different security report formats and preparation standards.
BoryShield XAI Solution can configure report templates to match the customer's reporting framework.
It can be expanded into various formats such as security operations reports, incident analysis reports, monthly reports, customer reports, and internal review reports.
7. Administrator Analysis Interface
Security personnel can use the administrator interface to review detection events, similar cases, analysis results, automatically generated reports, and review status.
Analysts can review AI-generated reports, revise or approve them as needed, and then use them for internal or customer reporting.
8. Integration with Existing Security Systems
BoryShield XAI Solution is not intended to replace existing security systems. It can be implemented to enhance the analysis, explanation, and reporting capabilities of those systems.
Depending on the customer environment, it can be integrated with the following systems.
- SIEM
- Security operations system
- Log collection system
- EDR/NDR
- IDS/IPS
- Firewall
- Web application firewall
- Threat intelligence system
- Internal reporting system
- Dashboard and monitoring interface
Available Implementation Configurations
Basic Implementation Configuration
- Security log input module
- Detection result integration module
- Data preprocessing module
- Vector embedding module
- Similarity search module
- Keyword search module
- LLM-based analysis module
- XAI explanation generation module
- Automated report generation module
- Administrator interface
- Report template management function
Extended Implementation Configuration
- SIEM integration
- EDR/NDR integration
- Threat intelligence integration
- On-premises deployment within an internal network
- Cloud-based deployment
- Customization of institution-specific report formats
- Security operations dashboard integration
- API-based delivery of analysis results
- Analyst review and approval process
- Automated monthly and weekly report generation
- Automation of customer-facing reports
- LLM model customization
- Security data vector database implementation
Application Scenarios
Security Operations Center Report Automation
The solution can be implemented as a system that analyzes events detected by a security operations center and automatically generates customer or internal reports.
Security operations personnel can reduce repetitive document preparation time and focus on critical threat assessment and response.
Advanced Threat Analysis for Enterprise Security Teams
Enterprise security teams can quickly understand threat context based on existing logs and detection results.
BoryShield XAI Solution searches for past attack cases similar to new events and organizes the analysis basis in natural language to support security personnel's decisions.
Security Reporting Framework for Public and Financial Institutions
Explainability and a structured reporting framework for security events are important to public and financial institutions.
BoryShield XAI Solution structures detection results, the basis for judgment, similar cases, and response references so they can be used for internal reporting and audit response materials.
Emerging Cyber Threat Analysis
New attack types, modified attacks, evasive attacks, and adversarial attacks may be difficult to analyze using simple keyword-based searches.
BoryShield XAI Solution uses vector-based similarity search and LLM-based explanations to compare new threat events with existing cases and organize the results into analysis sentences that security personnel can understand.
Security Data Analysis API Implementation
If a customer operates its own security platform, BoryShield XAI Solution's analysis results can be integrated through an API.
Threat explanations, similar-case search, and automated report generation can be added while retaining the existing interface.
Expected Benefits
Reduced Security Analysis Time
Repetitive log review and report preparation can be reduced, allowing security personnel to focus on actual threat assessment and response.
Standardized Report Quality
Security reports that were previously written differently by each person can be generated from standardized templates to maintain consistent reporting quality.
Enhanced Explainability of Detection Results
Instead of receiving only event alerts, users can also see why an event is considered a threat, which logs and indicators support that judgment, and which cases are similar.
Enhancement of Existing Security Systems
LLM-based analysis, XAI explanations, and report automation functions can be added while retaining existing security equipment and monitoring systems.
Foundation for Responding to Emerging Threats
Vector search and LLM analysis can help analyze threat events that are difficult to explain using existing rule-based detection more quickly.
Knowledge Transfer and Accumulation of Analysis Expertise
Accumulated analysis results and reports from security personnel can be used as an internal organizational knowledge asset for security analysis.
Implementation Process
1. Requirements Review
We review the customer's security operations method, security equipment configuration, report formats, data security policies, and internal network structure.
2. Data Structure Analysis
We review the available security logs, detection events, threat intelligence, existing reports, and analysis history data that can be integrated.
3. PoC Design
Using selected logs and detection results, we validate the feasibility of similarity search, threat explanation generation, and automated report generation.
4. Search and Analysis System Implementation
The vector database, keyword search, data preprocessing, LLM analysis, and XAI explanation generation architecture are implemented to suit the customer's environment.
5. Report Template Application
Automated templates are configured to match the customer's internal report format, security operations report format, and customer report format.
6. System Integration
The solution is integrated with the existing SIEM, log collection system, security operations dashboard, and internal reporting system.
7. Operational Validation and Enhancement
Analysis results and report quality are reviewed using actual security events and improved to match the customer's operating standards.
What You Can Do with BoryShield XAI Solution
- Implement a security log analysis system
- Automate explanations of threat detection results
- Search for similar security event cases
- Perform vector-based security data searches
- Search threat indicators by keyword
- Generate LLM-based threat analysis narratives
- Automatically generate XAI-based security reports
- Configure institution-specific report templates
- Automate security operations reporting tasks
- Integrate with existing SIEM and security operations systems
- Integrate threat intelligence data
- Implement a security analysis API
- Implement an internal-network-based security analysis system
- Implement a cloud-based security analysis service
- Implement an administrator interface for security personnel
Adoption Inquiries
BoryShield XAI Solution can be proposed as a PoC, internal-network deployment, cloud deployment, API integration, or report automation project tailored to the customer's security data structure, monitoring system, report formats, and internal security policies.
- Inquiry about adopting an LLM-based cyber threat analysis solution
- Inquiry about implementing security report automation
- Inquiry about security operations system integration
- Inquiry about implementing a threat similarity search system
- Inquiry about integration with an existing SIEM
- Inquiry about security analysis API development
- Inquiry about on-premises deployment within an internal network
- Inquiry about implementing a security reporting framework for public and financial institutions
- Request for a PoC proposal
Important Information
BoryShield XAI Solution is an AI-based security analysis solution that supports the analysis and explanation of security logs and threat detection results and automates report preparation.
This solution is not a standalone blocking device that replaces existing security equipment or security operations systems. It is an auxiliary analysis system that supports security personnel's analysis and reporting work.
We recommend that analysis results and automatically generated reports be used after review and approval by security personnel.
Threat analysis accuracy and report quality may vary depending on the customer's log quality, data structure, detection system configuration, training data, report templates, and security policies.
When security logs and internal system data are integrated, prior consultation is required regarding the customer's security policies, personal information protection standards, internal network configuration, access permissions, and data storage standards.
Before adoption, the target systems for integration, data formats, report formats, operating process, security policies, and deployment environment must be reviewed in advance.
BORY.ai Key Services Overview
Bory Co., Ltd. develops products, solutions, platforms, and services for industrial, medical, public-sector, healthcare, and barrier-free applications based on AI technologies involving speech, language, video, sensors, and data.
Below are the main representative domains currently operated or being prepared by Bory Co., Ltd.
| Primary Domain | Service/Brand | Description |
| bory.ai | BORY.ai | The official AI brand website of Bory Co., Ltd., serving as the company’s main website for the integrated presentation of its products, solutions, platforms, and services |
| borysense.com | BORY SENSE | An AI-powered hearing assistance platform that supports communication for people with hearing disabilities and older adults through real-time captioning, lip-reading AI, and AR glasses integration |
| borytalk.com | BORY TALK | A web-based conversational AI chatbot service designed for civil service inquiries, consultations, information guidance, and customer support |
| borykiosk.com | BORY KIOSK | A barrier-free AI kiosk service for older adults and people with disabilities, featuring voice guidance, captioning, and easy-to-use interfaces |
| boryservice.com | BORY SERVICE | A service portal introducing Bory’s AI services and custom-built AI offerings for industrial, public-sector, and everyday applications |
| borysong.com | BORY SONG | A music AI service that supports AI-powered composition, music generation, and sound content production |
'English > Solution(솔루션)' 카테고리의 다른 글
| Bory Tinnitus Biosignal Analysis Solution (0) | 2026.08.05 |
|---|---|
| BoryMed Solution (0) | 2026.08.05 |
| BoryRMS Solution (0) | 2026.08.05 |
| BorySafe Guard Solution (0) | 2026.08.05 |
| BoryForesight Solution (0) | 2026.08.05 |





최근댓글