{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T08:48:02Z","timestamp":1782809282609,"version":"3.54.5"},"reference-count":0,"publisher":"ECMS","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,6,23]]},"abstract":"<jats:p>Security Operations Centers (SOCs) continuously expand detection content, yet limited engineering capacity makes it difficult to decide which detection rules should be implemented, tuned, or reviewed first. This paper proposes a knowledge-driven method for prioritizing detection rules using the MITRE ATT&amp;CK framework and co-occurrence analysis of techniques. We construct a weighted technique co-occurrence graph from ATT&amp;CK STIX that uses relationships across campaigns and intrusion sets, and quantify technique importance using graph centrality measures (eigenvector, betweenness, and closeness). We then assign each rule a Priority Score by aggregating the importance of ATT&amp;CK techniques referenced by the rule, weighted by the technique's prevalence across threat entities.\n\nWe evaluate the approach offline on two public rule corpora (Sigma and Elastic) using a train\/test split of threat entities to avoid information leakage. Effectiveness is measured by Coverage@K and an importance-weighted variant that emphasizes centrally positioned techniques. The results show that frequency-only and centrality-only baselines are strong for maximizing unweighted technique coverage at small rule budgets, while the proposed Priority Score becomes more competitive under importance-weighted evaluation and can outperform baselines in selected settings. The findings indicate that technique co-occurrence centrality provides a transparent prioritization signal that aligns with emphasizing high-leverage techniques and suggest practical extensions, such as diversity-aware ranking and environment-specific calibration.<\/jats:p>","DOI":"10.7148\/2026-0295","type":"proceedings-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T08:36:46Z","timestamp":1782808606000},"page":"295-302","source":"Crossref","is-referenced-by-count":0,"title":["Prioritizing detection rules in soc using mitre att&amp;ck technique co-occurrence analysis"],"prefix":"10.7148","author":[{"given":"Kamil","family":"Wisniewski","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andrzej","family":"Mycek","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"4144","published-online":{"date-parts":[[2026,6,23]]},"event":{"name":"40th ECMS International Conference on Modelling and Simulation"},"container-title":["ECMS 2026 Proceedings edited by Filippo Sanfilippo, Florenc Demrozi, Fabio Sgarbossa, Mohammad Poursina"],"original-title":[],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T08:36:55Z","timestamp":1782808615000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.scs-europe.net\/dlib\/2026\/ecms2026acceptedpapers\/0295_secmos_ecms2026_0008.pdf"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,23]]},"references-count":0,"URL":"https:\/\/doi.org\/10.7148\/2026-0295","relation":{},"subject":[],"published":{"date-parts":[[2026,6,23]]}}}