用智能排序帮安全团队快速识别关键事件,提升响应效率。
Adaptive Incident Prioritization for Security Operations at Scale

- 将事件拆解为安全组件,结合频次、稀有度和领域权重动态打分
- 在1000家客户评估中,前10名准确率达92.8%
- 真实部署中显著提升分析师点击率,适合大规模安全运营场景
大型安全运营中心每天面临数百个活跃事件,分析师需在不断变化的队列中快速判断优先级,但传统按时间或粗粒度严重性排序难以明确相对重要性。我们提出自适应事件优先级算法(AIP),用于微软 Defender 队列助手,持续为分析师推荐待处理事件。AIP 将 BM25 思路适配到无查询、多租户队列场景,将每个事件表示为从告警与元数据中提取的标准化安全组件集合,融合局部组件频率、跨租户全局稀有度、有界领域先验乘子及组件级解释。系统部署于数万客户,支持近实时推理,事件评分刷新中位延迟仅5秒。在1000家客户机构的专家评估中,精确率@10达92.8%。上线后对47.3万组织-天队列的遥测数据显示,相较按严重性排序,事件详情点击量提升5.8%,查看事件量提升17.5%,表明模型排序更集中分析师注意力。我们还扩展了 Microsoft GUIDE 数据集,首次公开提供真实世界事件队列优先级标注——涵盖499个组织队列、9,980个事件,附专家标注标签,推动该领域研究发展。
原文摘要 · Abstract (English)
Large security operations centers (SOCs) often face hundreds of active incidents per day, creating substantial cognitive and operational demands for analysts. Analysts must quickly decide which incidents deserve attention within long, constantly changing queues, yet incidents are commonly ordered by arrival time, coarse severity, or product-specific heuristics that leave their relative priority unclear. We introduce Adaptive Incident Prioritization (AIP), the ranking algorithm behind Microsoft Defender Queue Assistant, which continuously prioritizes security incidents for analyst investigation. AIP adapts BM25-style ranking to a query-less, multi-tenant queue setting by representing each incident as a collection of normalized security components extracted from alerts and metadata. The model combines saturated local component frequency, global component rarity estimated across tenants, bounded domain-prior multipliers, and component-level explanations. Deployed across tens of thousands of customers, AIP performs near-real-time inference and refreshes incident scores with a median latency of five seconds. In an expert-reviewed evaluation across 1,000 customer organizations, AIP achieves 92.8% Precision@10. In post-launch telemetry across 473,000 organization-day queues, AIP increases alert-detail interaction by 5.8% and alert-detail view events by 17.5% relative to severity ordering, providing behavioral evidence that model-ranked queues concentrate analyst engagement. We also extend the Microsoft GUIDE dataset with, to our knowledge, the first public label source for SOC queue prioritization over real-world incidents. The extension covers 499 organization queues and 9,980 incidents with expert-derived priority labels, enabling the research community to develop, compare, and advance methods for incident prioritization.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。