Overview
This ongoing project focuses on building an AI-driven Security Operations Center (SOC) framework that detects and prioritizes security risk by learning from attack-surface drift and service behavior, rather than relying on traditional signature-based vulnerability scanners. The goal is to enable SOCs to identify persistent, exploitable conditions in rapidly changing environments where static scans and predefined vulnerability checks are increasingly ineffective.
Problem Statement
Modern infrastructures continuously change due to cloud elasticity, automated deployments, API evolution, and dynamic service exposure. Attackers exploit these conditions by monitoring exposure drift and acting when favorable configurations appear. Traditional vulnerability scanners provide snapshot assessments that often miss transient exposures, configuration drift, and previously unseen exploitation paths.
Approach
The framework operates on a fixed five-minute monitoring cadence and combines:
Attack-surface drift detection to identify changes in exposed ports and services
AI-based service behavior profiling using supervised and unsupervised machine learning
Anomaly detection to flag deviations from learned baselines
Risk-scoring models that estimate exploitability based on behavior, exposure persistence, and historical patterns
Instead of enumerating known CVEs, the system infers vulnerability by learning what exploitable services look like in practice, enabling detection of misconfigurations and zero-day-like conditions.
AI & Machine Learning Focus
Machine learning is used to:
Learn normal and abnormal service behavior over time
Detect anomalous protocol usage and configuration patterns
Score risk probabilistically using ensemble models
Reduce alert fatigue by suppressing transient noise
Adapt continuously through analyst feedback
Operational SOC Workflow
The project supports an end-to-end SOC lifecycle:
Continuous telemetry collection from exposed services
Feature extraction and normalization
AI-based vulnerability inference and scoring
Temporal correlation and persistence analysis
Analyst triage and validation
Response, remediation, and verification
Feedback-driven model refinement
Validation Environment
The framework is evaluated in a controlled laboratory using intentionally vulnerable systems (Kioptrix 2 and Metasploitable 2) within a DMZ-style segmented network, ensuring ethical testing and realistic SOC deployment conditions.
Current Outcomes
Preliminary results show:
Improved prioritization of high-risk, persistent exposures
Reduced analyst workload through AI-assisted filtering
Earlier identification of exploitable conditions compared to static scans
Stable performance in both low-signal and high-noise environments
Threat-Informed Context
AI-inferred weaknesses are mapped to adversary behaviors using the MITRE ATT&CK framework, enabling threat-informed SOC decision-making and alignment with real attacker workflows.
Status
Ongoing - Active Development
Planned Enhancements
Advanced time-series learning (LSTM / Bayesian models)
Adaptive baselining per service and environment
SOC dashboards and analyst feedback loops
SIEM integration for real-time security analytics
Core Technologies
AI & Machine Learning · Anomaly Detection · Risk Scoring · Python · SOC Analytics · Continuous Monitoring · MITRE ATT&CK · Autonomous Security Analytics