Structuring Security: A Survey of Cybersecurity Ontologies, Semantic Log Processing, and LLMs Application
Bruno Lourenço, Pedro Adão, João F. Ferreira, Mario Monteiro Marques, Cátia Vaz
TL;DR
This survey assesses how cybersecurity ontologies, semantic log processing, and large language models (LLMs) collectively advance threat reasoning and defense. It maps ontology usage and LLM/semantic-log integration across eight JRC Cybersecurity Taxonomy domains, highlighting strong formal ontology work but limited knowledge graphs, logs, and hybrid AI deployments. The analysis reveals persistent gaps in formal validation (V&V), standardization, and cross-domain interoperability, while underscoring opportunities for neuro-symbolic methods and dynamic ontology evolution guided by LLMs and logs. The work aligns with EU regulatory aims (NIS 2) and emphasizes the need for FAIR-compliant, publicly accessible ontologies to accelerate adoption and collaboration in intelligent cyber defense.
Abstract
This survey investigates how ontologies, semantic log processing, and Large Language Models (LLMs) enhance cybersecurity. Ontologies structure domain knowledge, enabling interoperability, data integration, and advanced threat analysis. Security logs, though critical, are often unstructured and complex. To address this, automated construction of Knowledge Graphs (KGs) from raw logs is emerging as a key strategy for organizing and reasoning over security data. LLMs enrich this process by providing contextual understanding and extracting insights from unstructured content. This work aligns with European Union (EU) efforts such as NIS 2 and the Cybersecurity Taxonomy, highlighting challenges and opportunities in intelligent ontology-driven cyber defense.
