Stop Feeding the SOC Garbage
Security operations teams are handling increasing volumes of network events and security alerts. Whether those alerts are reviewed by human analysts, processed by AI, or handled through a combination of both, the result depends on the quality of the underlying detections.
No SOC can investigate an intrusion that never generated an alert. And if the incoming alerts are incomplete, noisy, or biased toward known attack patterns, the result is inefficient investigations and missed malicious activity.
Simply spending more on AI tokens will not solve this problem. AI can prioritize, correlate, and summarize the alerts it receives, but it cannot recover activity that was never detected or reliably compensate for systematically noisy inputs. Detection quality still depends on input quality. Or in other words, Garbage-In-Garbage-Out (GIGO) still applies.
False positives and false negatives
False positives are a constant pain for many SOCs. They waste analyst time, cause alert fatigue, and may lead teams to disable or ignore useful detections. So-called benign alerts are almost just as bad. This image shared by @cR0w humorously captures the analyst experience.
While false positives waste time, false negatives may waste nothing at all. That's an even bigger problem!
A different way to identify protocols
Traditional intrusion detection systems (IDS) are valuable, but they depend on static signatures and protocol-specific rules. Creating a reliable signature can require expertise and large PCAP datasets to test for false positives. Some protocols are especially difficult to detect with such techniques. They may be proprietary, undocumented, encrypted, obfuscated, or designed to resemble benign traffic.
FlowCarp takes a different approach. It identifies application-layer protocols by analyzing statistical characteristics of network traffic and comparing them with models of known protocols. This does not require a formal protocol specification. A protocol model can be created from example traffic, including traffic from a protocol that is difficult to express as a conventional IDS signature.
FlowCarp can identify both legitimate and malicious protocols, including protocols used for malware command-and-control (C2) traffic. It can also generate alerts and integrate with existing monitoring workflows.
A complementary detection method
FlowCarp is not intended to replace a traditional IDS. One of its key features is that it provides another view of network activity.
A traditional IDS signature may stop matching when an attacker changes an indicator. A parser may not support an undocumented protocol. A port-based rule may fail when traffic moves to an unexpected port. Because it identifies protocols based on statistical traffic characteristics, FlowCarp can provide an alternative when static signatures and protocol parsers are unavailable, insufficient, or unreliable.
The reverse can also be true: a conventional signature may be the better detector in a particular situation. Using different detection methods together can make monitoring more resilient.
This additional perspective is useful in any SOC. These alerts can provide additional investigative leads for analysts and additional evidence for automated triage systems. In both cases, the benefit depends on receiving alerts that are relevant and accurate.
Better detection benefits every SOC
The goal should not simply be to maximize the number of alerts a SOC can process. It should be to produce alerts that cover meaningful activity without overwhelming the people and systems responsible for investigating them.
Whether a SOC relies on human analysts, AI, or a combination of both, the foundation is the same: high-quality inputs lead to better detections. Before asking a SOC to handle higher alert volumes, it is worth asking whether those alerts provide an accurate view of the network and what might still be missing.
Posted by Erik Hjelmvik on Tuesday, 06 October 2026 06:30:00 (UTC/GMT)
Tags: #FlowCarp