IOC Analysis Model for SOC Alert Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The workload of analysts in Security Operation Centers (SOCs) remains high due to the need for manual evaluation of individual alerts, despite existing techniques that focus on improving analysis efficiency for individual alerts rather than reducing the overall number of analysis operations.

Innovation Solution

A determination method and apparatus that extracts feature information from indicators of compromise (IOCs), labels IOCs based on actual workload requirements, and learns a model to predict and prioritize IOCs for analysts, reducing manual investigation and automating alert analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If analysts manually evaluate individual alerts to ensure security accuracy, then measurement precision is improved, but productivity deteriorates due to high workload and alert fatigue

Engineering Contradiction:
Improvealert analysis accuracyVSAvoidanalyst productivity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent segments the alert evaluation process into two distinct paths: a first evaluation process for alerts with low abnormality scores (processed automatically with standardized responses) and a second evaluation process for alerts with high abnormality scores (processed manually by analysts). This segmentation allows routine alerts to be handled automatically, reducing analyst workload, while maintaining manual review for suspicious alerts to ensure accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements self-service automation where the alert management system automatically evaluates alerts using machine learning models, determines abnormality scores, and executes standardized response processes for low-risk alerts without human intervention. This self-service capability reduces the burden on analysts while maintaining security effectiveness.

Inventive Principle:
Principle #25Self-service

2Productivity

If automation is increased to reduce analyst workload, then productivity is improved, but measurement precision deteriorates due to potential false positives and negatives

Engineering Contradiction:
Improvealert processing throughputVSAvoidalert classification accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where analysts review and correct automated evaluations, and these corrections are used to retrain and improve the machine learning models. The system continuously learns from analyst feedback, adjusting the abnormality score thresholds and evaluation criteria to reduce false positives and negatives over time.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary automated evaluation of all alerts before they reach analysts, pre-filtering and scoring alerts based on multiple features and historical data. This preliminary action prepares alerts for either automatic resolution or targeted manual review, improving overall system efficiency while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If all alerts are evaluated manually to maintain security standards, then measurement precision is improved, but loss of time increases due to alert fatigue and burnout

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidanalyst time consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements dynamic alert routing where the evaluation process adapts based on the calculated abnormality score. Alerts are dynamically assigned to different processing paths (automatic or manual) based on their risk level, allowing the system to flexibly allocate analyst time to high-priority alerts while automating routine evaluations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of analyst involvement based on the abnormality score of each alert. For alerts with abnormality scores below a threshold, the parameter of human review is changed to automatic processing. For alerts above the threshold, manual review is maintained. This parameter change optimizes both time efficiency and security accuracy.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240248986A1Determination method, determination device, and determination program
Publication Date: 2024.07.25 NT T INC
  • US20240248986A1 patent drawing
  • US20240248986A1 patent drawing
  • US20240248986A1 patent drawing

AI summary

A determination method executed by a determination apparatus includes extracting feature information from an indicator of compromise (IOC) included in information related to cyber security, imparting a label to each of IOCs according to an actual result of a workload required for dealing with a relevant alert, and learning a model for outputting a label from feature information of an IOC by using learning data obtained by combining the feature information extracted with the label imparted.