Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

Visualization Techniques for Computer Network Defense

Conference ·
OSTI ID:1018615

Effective visual analysis of computer network defense (CND) information is challenging due to the volume and complexity of both the raw and analyzed network data. A typical CND is comprised of multiple niche intrusion detection tools, each of which performs network data analysis and produces a unique alerting output. The state-of-the-practice in the situational awareness of CND data is the prevalent use of custom-developed scripts by Information Technology (IT) professionals to retrieve, organize, and understand potential threat events. We propose a new visual analytics framework, called the Oak Ridge Cyber Analytics (ORCA) system, for CND data that allows an operator to interact with all detection tool outputs simultaneously. Aggregated alert events are presented in multiple coordinated views with timeline, cluster, and swarm model analysis displays. These displays are complemented with both supervised and semi-supervised machine learning classifiers. The intent of the visual analytics framework is to improve CND situational awareness, to enable an analyst to quickly navigate and analyze thousands of detected events, and to combine sophisticated data analysis techniques with interactive visualization such that patterns of anomalous activities may be more easily identified and investigated.

Research Organization:
Oak Ridge National Laboratory (ORNL)
Sponsoring Organization:
ORNL work for others
DOE Contract Number:
AC05-00OR22725
OSTI ID:
1018615
Country of Publication:
United States
Language:
English

Similar Records

Analytics for Cyber Network Defense
Technical Report · Wed Jun 01 00:00:00 EDT 2011 · OSTI ID:1113857

Securing Grid-interactive Efficient Buildings (GEB) through Cyber Defense and Resilient System (CYDRES)
Technical Report · Mon Mar 25 00:00:00 EDT 2024 · OSTI ID:2331215

Resource Forecast and Ramp Visualization for Situational Awareness (RAVIS)
Software · Thu Mar 04 19:00:00 EST 2021 · OSTI ID:code-55145