Why Additive Risk Scoring Fails Against High-Confidence Threat Intel Signals
A cybersecurity team discovered that their purely additive risk-scoring model was dangerously under-reacting to high-confidence threat intelligence hits. In one case, an IP confirmed by ThreatFox as active Cobalt Strike command-and-control infrastructure scored only 33 out of 100, landing in the 'LOW' severity tier and bypassing automated review. The root problem was that the additive model treated a definitive malicious confirmation as just another point contributor, equal in weight to weak probabilistic signals like unusual user-agent strings. The team resolved this by introducing a score floor rule: any single authoritative confirmation of malicious activity — from sources like ThreatFox, OTX, GreyNoise, or AbuseIPDB — automatically sets the event score to a minimum of 75, triggering full analysis. The broader takeaway is that additive scoring suits weak-to-moderate signals but must be paired with floor rules when any signal is meant to convey near-certainty of a threat.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in