IOC Analysis Model for SOC Alert Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The workload of analysts in Security Operation Centers (SOCs) remains high due to the need for manual evaluation of individual alerts, despite existing techniques that focus on improving analysis efficiency for individual alerts rather than reducing the overall number of analysis operations.
Innovation Solution
A determination method and apparatus that extracts feature information from indicators of compromise (IOCs), labels IOCs based on actual workload requirements, and learns a model to predict and prioritize IOCs for analysts, reducing manual investigation and automating alert analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If analysts manually evaluate individual alerts to ensure security accuracy, then measurement precision is improved, but productivity deteriorates due to high workload and alert fatigue
Solution Approach 1:
The patent segments the alert evaluation process into two distinct paths: a first evaluation process for alerts with low abnormality scores (processed automatically with standardized responses) and a second evaluation process for alerts with high abnormality scores (processed manually by analysts). This segmentation allows routine alerts to be handled automatically, reducing analyst workload, while maintaining manual review for suspicious alerts to ensure accuracy.
Solution Approach 2:
The system implements self-service automation where the alert management system automatically evaluates alerts using machine learning models, determines abnormality scores, and executes standardized response processes for low-risk alerts without human intervention. This self-service capability reduces the burden on analysts while maintaining security effectiveness.
2Productivity
If automation is increased to reduce analyst workload, then productivity is improved, but measurement precision deteriorates due to potential false positives and negatives
Solution Approach 1:
The patent implements feedback mechanisms where analysts review and correct automated evaluations, and these corrections are used to retrain and improve the machine learning models. The system continuously learns from analyst feedback, adjusting the abnormality score thresholds and evaluation criteria to reduce false positives and negatives over time.
Solution Approach 2:
The system performs preliminary automated evaluation of all alerts before they reach analysts, pre-filtering and scoring alerts based on multiple features and historical data. This preliminary action prepares alerts for either automatic resolution or targeted manual review, improving overall system efficiency while maintaining accuracy.
3Measurement precision
If all alerts are evaluated manually to maintain security standards, then measurement precision is improved, but loss of time increases due to alert fatigue and burnout
Solution Approach 1:
The patent implements dynamic alert routing where the evaluation process adapts based on the calculated abnormality score. Alerts are dynamically assigned to different processing paths (automatic or manual) based on their risk level, allowing the system to flexibly allocate analyst time to high-priority alerts while automating routine evaluations.
Solution Approach 2:
The system changes the parameter of analyst involvement based on the abnormality score of each alert. For alerts with abnormality scores below a threshold, the parameter of human review is changed to automatic processing. For alerts above the threshold, manual review is maintained. This parameter change optimizes both time efficiency and security accuracy.
Data Source
AI summary
A determination method executed by a determination apparatus includes extracting feature information from an indicator of compromise (IOC) included in information related to cyber security, imparting a label to each of IOCs according to an actual result of a workload required for dealing with a relevant alert, and learning a model for outputting a label from feature information of an IOC by using learning data obtained by combining the feature information extracted with the label imparted.


