IOC Feature Extraction for SOC Analyst Workload Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security operation center (SOC) systems fail to effectively determine the priority of indicator of compromise (IOC) investigations, leading to inefficiencies and analyst burnout due to inadequate automation and feature information utilization.
Innovation Solution
An extraction method and device that acquire and analyze the history of analyst actions on IOCs to create feature information, using machine learning to predict IOC priority and automate the investigation process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual analysis of all security alerts is performed by analysts, then detection accuracy is maintained, but analyst workload increases leading to burnout and reduced productivity
Solution Approach 1:
The patent introduces an automated analysis system that acts as an intermediary between security alerts and human analysts. This system extracts feature information from alerts and performs preliminary analysis, serving as a mediator that handles routine processing while allowing analysts to focus on complex cases, thereby maintaining detection accuracy while reducing workload
Solution Approach 2:
The system enables self-service by automatically extracting and analyzing feature information from security alerts without requiring manual analyst intervention for every alert. The automated feature extraction and analysis capabilities allow the system to serve itself in processing routine alerts, freeing analysts from repetitive tasks
2Productivity
If automation is increased to reduce analyst workload, then productivity improves, but the ability to accurately determine IOC investigation priority deteriorates
Solution Approach 1:
The system implements feedback mechanisms where analysis results and feature information are continuously refined based on outcomes. The automated system learns from analysis patterns and adjusts its feature extraction and priority determination processes, improving accuracy over time while maintaining high automation levels
Solution Approach 2:
The patent replaces manual mechanical analysis processes with automated information processing systems. By substituting human manual evaluation with automated feature extraction and analysis algorithms, the system achieves high productivity while maintaining or improving determination accuracy through consistent, data-driven analysis
3Speed
If feature information extraction is automated, then analysis speed increases, but the complexity of the extraction system increases
Solution Approach 1:
The feature extraction system is segmented into modular components that handle different aspects of information extraction independently. This segmentation allows the system to achieve high analysis speed through parallel processing while managing complexity by dividing the extraction task into manageable, specialized modules
Solution Approach 2:
The extraction system is designed with universal, multi-functional components that can handle various types of security alerts and extract relevant feature information across different contexts. This multi-functionality reduces overall system complexity by using standardized approaches rather than requiring separate specialized systems for each alert type
Data Source
AI summary
A feature information extraction unit acquires a history of actions taken by an analyst with respect to investigation of an IOC included in information on cyber security. A feature information extraction unit creates IOC feature information on the basis of information obtained from the acquired history of actions.


