詳細検索

Will AI replace SOC? What is the realistic future for corporate security operations?

Avatar
by 西田
3 min read

Will AI replace SOC? What is the realistic future for corporate security operations?
Translated from 日本語 • View original
西田
西田

〜To the era of "judgment assistance" rather than "automation"〜Hello, this is Nishida from Colorkrew Security. Generative AI and automation technologies are rapidly evolving, and we are now hearing voices saying, "Will AI eliminate SOC operations?"

Indeed, AI can speed up "analysis", "summary", and "classification" in security operations.
However, in conclusion -

**AI cannot "replace" SOC. **
However, you can "harden" your SOC.

1. The job of a SOC is to "make decisions and prioritize"

The core business of the SOC (Security Operation Center) is
It's not just about reviewing alerts and analyzing logs.

In fact, the following flow is repeated.

  1. Check for alerts
  2. Examine Related Logs
  3. Determine the presence of a threat
  4. Prioritize and decide on a response
  5. Leave as knowledge

In other words, the essence of SOC is not "information processing", but "decision-making".
This "judgment" part is also the area where AI is most weak.

2. Where AI is good at and where it is not good

Domain Good at AI Not good at AI
Data Analytics Log Summarization, Correlation & Classification Guessing the Context, Intent, and Purpose of the Attack
Alert Response Initial Ticket Creation, Routine Survey Prioritization and Risk Assessment
Reporting Article Generation & Shaping Reflecting Company Characteristics and Customer Context
Threat Hunting Extracting Known Patterns Insight into Unknown Behavior and Human Intentions

AI is excellent in "data processing power",
I do not have the "ability to understand and judge the background and intention".

For example, even in the same communication
To distinguish between "admin testing" and "internal fraud", use
It requires a human eye to know the context and behavior of the organization.

3. Three areas where AI can "enhance" SOC

Still, AI will definitely streamline SOC operations.
The key is to design "how far to leave AI and where to intervene."

(1) Summary and Summary of Alerts

The AI summarizes logs and alerts in natural language to organize the information you need to investigate.
→ Analysts can reduce "reading time" and increase "thinking time".

(2) Knowledge Search and Reuse

AI searches, summarizes, and presents past incident records.
→ Immediately grasp whether there were similar cases.

(3) Automatic ticketing and notification

AI organizes alert content,
Automatically assign response personnel and procedures.
→ People can focus on what they need to do first.

In these areas, AI acts as a "supporter" rather than a "replacement".

4. "You can automate with AI" and "You can leave it to AI" are different.

Just because AI can automate
It is not always okay to leave it as it is.

Many SOC tasks are
"Do you respond to false positives just in case?"
It involves risk judgments such as "Do you need to report to the customer?"

What AI lacks is accountability.
Why did you come to that decision, and who will take responsibility?
This area is the part that the human SOC should be responsible for until the end.

5. Colorkrew Security's Approach

Colorkrew Security uses AI as a "mechanism to assist people in making decisions."

  • A system that allows AI to refer to and propose SOC operation knowledge
  • Alert summary, automatic classification, and initial response support
  • Operational design in which "human review" of AI-based decisions

**AI evolves SOC, not reduces it. **
That is the form of "AI ×SOC" that we are aiming for.

Related Articles