CRDec 2, 2021

A tool to support the investigation and visualization of cyber and/or physical incidents

arXiv:2112.01103v12 citations
Originality Synthesis-oriented
AI Analysis

This addresses the challenge for security operators in efficiently detecting and understanding cyber or physical incidents, though it appears incremental as it builds on existing monitoring solutions.

The paper tackles the problem of security operators being overwhelmed by vast amounts of information during incident investigations by developing a tool that combines a dynamic user interface with machine learning forecasts to facilitate their work, resulting in an intelligent investigation tool that can also provide automated decision support.

Investigating efficiently the data collected from a system's activity can help to detect malicious attempts and better understand the context behind past incident occurrences. Nowadays, several solutions can be used to monitor system activities to detect probable abnormalities and malfunctions. However, most of these systems overwhelm their users with vast amounts of information, making it harder for them to perceive incident occurrences and their context. Our approach combines a dynamic and intuitive user interface with Machine Learning forecasts to provide an intelligent investigation tool that facilitates the security operator's work. Our system can also act as an enhanced and fully automated decision support mechanism that provides suggestions about possible incident occurrences.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes