IOC Feature Extraction for SOC Investigation Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security operation center (SOC) systems face challenges in determining the priority of indicator of compromise (IOC) investigations due to a lack of feature information necessary for assessing whether an IOC is abnormal or malignant, leading to inefficient analyst operations.
Innovation Solution
An extraction method and device that acquire and create feature information for IOCs based on observation results from security appliances, utilizing threat intelligence services and DNS databases to characterize IOC characteristics, enabling prioritization of IOC investigations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automation level is increased to reduce analyst workload, then productivity is improved, but the system lacks sufficient feature information to accurately determine IOC investigation priority
Solution Approach 1:
The system performs preliminary extraction and organization of feature information from observation results before IOC priority determination. By pre-processing and structuring the feature information from security appliance observations, the system prepares comprehensive data in advance that enables accurate automated priority assessment, thereby improving productivity without information loss.
Solution Approach 2:
The patent introduces an intermediary extraction device that bridges the gap between raw observation results and IOC priority determination. This intermediary component extracts and structures feature information from observation results, transforming unprocessed data into organized features that can be effectively used by automation systems to determine IOC priorities accurately.
2Measurement precision
If more feature information is extracted from observation results, then measurement precision of IOC characteristics is improved, but device complexity increases
Solution Approach 1:
The extraction device is segmented into functional modules that handle different aspects of feature information extraction from observation results. By dividing the extraction process into discrete, specialized components, the system achieves comprehensive feature extraction with improved measurement precision while managing device complexity through modular architecture.
Solution Approach 2:
The extraction device is designed with multi-functional capabilities to handle various types of observation results and extract diverse feature information using a unified framework. This universal approach enables the system to achieve high measurement precision across different IOC types without proportionally increasing device complexity, as the same extraction mechanisms serve multiple purposes.
Data Source
AI summary
An extraction method executed by an extraction device includes acquiring an observation result by a predetermined organization with respect to an indicator of compromise (IOC) included in information on cyber security, and creating feature information of the IOC based on information obtained from the observation result acquired.


