Research Article

Analyst-Aware Incident Assignment in Security Operations Centers: A Multi-Factor Prioritization and Optimization Framework

Volume: 8 Number: 4 July 15, 2025
EN TR

Analyst-Aware Incident Assignment in Security Operations Centers: A Multi-Factor Prioritization and Optimization Framework

Abstract

In this paper, we propose a comprehensive and scalable framework for incident assignment and prioritization in Security Operations Centers (SOCs). The proposed model aims to optimize SOC workflows by addressing key operational challenges such as analyst fatigue, alert overload, and inconsistent incident handling. Our framework evaluates each incident using a multi-factor scoring model that incorporates incident severity, service-level agreement (SLA) urgency, incident type, asset criticality, threat intelligence indicators, frequency of repetition, and a correlation score derived from historical incident data. We formalize this evaluation through a set of mathematical functions that compute a dynamic incident score and derive incident complexity. In parallel, analyst profiles are quantified using Analyst Load Factor (ALF) and Experience Match Factor (EMF), two novel metrics that account for both workload distribution and expertise alignment. The incident–analyst matching process is expressed as a constrained optimization problem, where the final assignment score is computed by balancing incident priority with analyst suitability. This formulation enables automated, real-time assignment of incidents to the most appropriate analysts, while ensuring both operational fairness and triage precision. The model is validated using algorithmic pseudocode, scoring tables, and a simplified case study, which illustrates the real-world applicability and decision logic of the framework in large-scale SOC environments. To validate the framework under real-world conditions, an empirical case study was conducted using 10 attack scenarios from the CICIDS2017 benchmark dataset. Overall, our contributions lie in the formalization of a dual-factor analyst scoring scheme and the integration of contextual incident features into an adaptive, rule-based assignment framework. To further strengthen operational value, future work will explore adaptive weighting mechanisms and integration with real-time SIEM pipelines. Additionally, feedback loops and supervised learning models will be incorporated to continuously refine analyst-incident matching and prioritization.

Keywords

References

  1. Al-Dhaqm A, Siddique K, Abd Razak S, Ikuesan RA, Kebande VR. 2020. Towards the development of an integrated incident response model for database forensic investigation field. IEEE Access, 8: 145018-145032.
  2. Alrimawi F, Pasquale L, Nuseibeh B. 2019. On the automated management of security incidents in smart spaces. IEEE Access, 7: 111513-111527.
  3. AXELOS. 2019. ITIL Foundation: ITIL 4 Edition. The Stationery Office (TSO), London, UK, 1st ed., pp. 1-255.
  4. Binbeshr F, Imam M, Hamdan M, Ghaleb M, Rahim MA, Hammoudeh M. 2025. The rise of cognitive SOCs: A systematic literature review on AI approaches. IEEE Open J Comput Soc, 6: 360-379.
  5. Chhetri MB, Tariq S, Singh R, Jalalvand F, Paris C, Nepal S. 2024. Towards human-AI teaming to mitigate alert fatigue in security operations centres. ACM Comput Surv, 24(3): 1-22.
  6. Gachnang P, Ehrenthal J, Telesko R, Hanne T. 2023. Determination of weights for multiobjective combinatorial optimization in incident management with an evolutionary algorithm. IEEE Access, 11: 138502-138514.
  7. García LA, Tomás VR. 2020. A framework for enhancing the operational phase of traffic management plans. IEEE Access, 8: 204483-204493.
  8. Handri EY, Sensuse DI, Tarigan A. 2025. Developing an agile cybersecurity framework with organizational culture approach using Q methodology. IEEE Access, 13: 108835-108850.

Details

Primary Language

English

Subjects

Information Security Management, Information Systems Organisation and Management

Journal Section

Research Article

Early Pub Date

July 9, 2025

Publication Date

July 15, 2025

Submission Date

May 6, 2025

Acceptance Date

June 16, 2025

Published in Issue

Year 2025 Volume: 8 Number: 4

APA
Kilincdemir, E. C., & Celiktas, B. (2025). Analyst-Aware Incident Assignment in Security Operations Centers: A Multi-Factor Prioritization and Optimization Framework. Black Sea Journal of Engineering and Science, 8(4), 1160-1180. https://doi.org/10.34248/bsengineering.1693042
AMA
1.Kilincdemir EC, Celiktas B. Analyst-Aware Incident Assignment in Security Operations Centers: A Multi-Factor Prioritization and Optimization Framework. BSJ Eng. Sci. 2025;8(4):1160-1180. doi:10.34248/bsengineering.1693042
Chicago
Kilincdemir, Eyup Can, and Baris Celiktas. 2025. “Analyst-Aware Incident Assignment in Security Operations Centers: A Multi-Factor Prioritization and Optimization Framework”. Black Sea Journal of Engineering and Science 8 (4): 1160-80. https://doi.org/10.34248/bsengineering.1693042.
EndNote
Kilincdemir EC, Celiktas B (July 1, 2025) Analyst-Aware Incident Assignment in Security Operations Centers: A Multi-Factor Prioritization and Optimization Framework. Black Sea Journal of Engineering and Science 8 4 1160–1180.
IEEE
[1]E. C. Kilincdemir and B. Celiktas, “Analyst-Aware Incident Assignment in Security Operations Centers: A Multi-Factor Prioritization and Optimization Framework”, BSJ Eng. Sci., vol. 8, no. 4, pp. 1160–1180, July 2025, doi: 10.34248/bsengineering.1693042.
ISNAD
Kilincdemir, Eyup Can - Celiktas, Baris. “Analyst-Aware Incident Assignment in Security Operations Centers: A Multi-Factor Prioritization and Optimization Framework”. Black Sea Journal of Engineering and Science 8/4 (July 1, 2025): 1160-1180. https://doi.org/10.34248/bsengineering.1693042.
JAMA
1.Kilincdemir EC, Celiktas B. Analyst-Aware Incident Assignment in Security Operations Centers: A Multi-Factor Prioritization and Optimization Framework. BSJ Eng. Sci. 2025;8:1160–1180.
MLA
Kilincdemir, Eyup Can, and Baris Celiktas. “Analyst-Aware Incident Assignment in Security Operations Centers: A Multi-Factor Prioritization and Optimization Framework”. Black Sea Journal of Engineering and Science, vol. 8, no. 4, July 2025, pp. 1160-8, doi:10.34248/bsengineering.1693042.
Vancouver
1.Eyup Can Kilincdemir, Baris Celiktas. Analyst-Aware Incident Assignment in Security Operations Centers: A Multi-Factor Prioritization and Optimization Framework. BSJ Eng. Sci. 2025 Jul. 1;8(4):1160-8. doi:10.34248/bsengineering.1693042

                            24890