A global transition toward intelligent security infrastructures is demonstrated, with measurable improvements in performance, accuracy, and response times in the generation of actionable intelligence to support strategic decision-making.
Abstract
Security infrastructure has evolved from the use of reactive models toward the adoption of predictive technologies, transforming and enhancing threat anticipation, improving monitoring capabilities, and strengthening strategic decision-making driven by the integration of emerging technologies and artificial intelligence. This review study synthesizes the changes occurring across spatial, maritime, aerial, border, and cybersecurity infrastructure, evidencing the impact of the transition toward predictive technologies; it addresses the challenges and limitations these technologies introduce as a consequence of their operational deployment, and concludes by examining future lines of development in this domain. The review was conducted following the PRISMA® methodology, analyzing the scientific literature retrieved from seven indexed databases—SCOPUS, ScienceDirect, Web of Science, IEEE Xplore, Taylor & Francis, ProQuest, and PubMed—consistent with the full search scope. Articles were independently assessed by two reviewers, yielding an initial Cohen’s Kappa coefficient of 0.458; following structured discussion and consensus resolution, the final inter-rater reliability reached κ = 0.71, meeting the accepted threshold for scoping review methodology. The findings demonstrate a global transition toward intelligent security infrastructures, with measurable improvements in performance, accuracy, and response times in the generation of actionable intelligence to support strategic decision-making.
To improve cybersecurity across industries, Cyber Threat Intelligence (CTI) is becoming increasingly crucial. This systematic review explores how CTI practices are evolving in response to advancements in Artificial Intelligence (AI), particularly in the context of Large Language Models (LLMs). We examined 61 peer-reviewed studies using the PRISMA methodology, which demonstrates a strict selection procedure founded on specified inclusion, exclusion, and quality standards. This approach aligns with the scope of similar systematic reviews in the field of cyber threat intelligence. The review provides a comparative synthesis of CTI research capabilities across threat detection and prediction, attribution, forecasting, and automated reporting. We classify these approaches into three categories: conventional methods, those enhanced by AI and Machine Learning, and those based on LLMs. Our findings indicate that LLMs offer significant advantages in contextual reasoning, processing unstructured threat intelligence, and generating actionable mitigation plans. However, challenges such as model explainability, data privacy, system interoperability, and standardization impede their integration into operational environments. In addition to highlighting the potential and practical limitations of LLMs in CTI, this study identifies research gaps and proposes methods to create scalable, secure, and flexible CTI systems that support real-time cyber defense.
Hilalah Alturkistani, Abdul Ghafar Jaafar, S. Chuprat et al.· International journal of res...· 0 citations
A structured taxonomy is proposed to organize various dimensions of AI-driven cybersecurity; review them critically; and finally, discuss key challenges, open problems, and emerging trends.
The case is made for a first-principles approach that CTI teams can adopt as an unbiased anchor to guide their decisions around establishing an adequate CTI capability, and pragmatic recommendations to assist CTI teams with qualifying their prospective vendors to ensure good fit are offered.
Aaron Aubrey Ng· International Conference on...· 0 citations
A multi-layered safety model that integrates emerging technologies with human-centred practices, emphasising resilience engineering, adaptive training, transparent AI governance, and continuous learning across transportation ecosystems is proposed, arguing that technological innovation must be framed not as a replacement for human expertise but as an enabler of enhanced human performance.
This review provides a novel synthesis of recent Large Language Model applications in threat hunting and identifies critical research gaps, and presents a refined perspective on the practical implementation and future trajectory of these technologies.
The article examines the transition from scheduled security assessments to continuous vulnerability management frameworks in enterprise environments with unstable external exposure. Cloud services, SaaS use, short-lived assets, and unmanaged public interfaces reduce the decision value of annual or project-based testing. The novelty of the study lies in combining external attack surface management, continuous penetration testing, vulnerability intelligence, and remediation verification into a single operating model. The aim is to explain why periodic assessment loses completeness when asset states change between review cycles. The method combines source analysis, comparative analysis, conceptual synthesis, and typological classification. The source base covers academic papers, public vulnerability intelligence instruments, official guidance, and industry definitions of external attack surface management. The study identifies three shifts: from snapshot testing to continuous discovery, from severity ranking to exploitation-aware prioritisation, and from automated scanning to expert-verified remediation. The model helps engineering and security teams design measurable programs to reduce exposure.
Kolchin Rustam· International Research Journ...· 0 citations