Intelligent priority awareness method for alert data in SOC threat response
Abstract
The Security Operations Center (SOC) is a key operational platform in modern enterprise cybersecurity architectures, where alert monitoring, threat detection, and incident response must be performed under high-volume and high-noise conditions. Detection is increasingly challenged by cyberattacks with growing complexity, novelty, coordination, and stealth, resulting in massive false positives, difficulty in identifying high-risk alerts, analyst fatigue, and delayed response. This study proposes an intelligent priority awareness method for SOC alert data. First, a hierarchical alert noise reduction method is designed by combining Fast Fourier Transform-Pearson Correlation Coefficient (FFT-PCC) filtering with BERT-assisted multi-agent evidence orchestration. To prevent periodic but genuinely high-risk alerts from being mistakenly removed, the FFT-PCC module is constrained by a conservative risk-gated filtering rule that forwards any alert with threat-intelligence, asset-criticality, or attack-stage evidence to deeper analysis. On the labeled benchmark, the method achieves an AUC of 0.973, an accuracy of 0.9467, a precision of 0.923, a recall of 0.897, and an F1-score of 0.910 for false-positive alert identification. In a separate production-stream usability evaluation, it achieves a 72.0% alert noise reduction rate. Second, a dynamic risk scoring system is constructed by integrating cybersecurity knowledge graphs, asset-vulnerability association graphs, formal semantic integrity verification, and Analytic Hierarchy Process (AHP)-based weighting. Finally, an end-to-end SOC priority awareness framework is implemented and evaluated against commercial and open-source SOC platforms. The framework reduces mean threat response time by 45.2%, increases alert processing throughput by 103%, and lowers analyst cognitive load by 37%. The results indicate that the framework can support earlier triage, more reliable alert prioritization, and more efficient SOC threat response under high-noise operational conditions.