Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

Putting Security in Context: Visual Correlation of Network Activity with Real-World Information

Conference ·

To effectively identify and respond to cyber threats, computer security analysts must understand the scale, motivation, methods, source, and target of an attack. Central to developing this situational awareness is the analyst’s world knowledge that puts these attributes in context. What known exploits or new vulnerabilities might an anomalous traffic pattern suggest? What organizational, social, or geopolitical events help forecast or explain attacks and anomalies? Few visualization tools support creating, maintaining, and applying this knowledge of the threat landscape. Through a series of formative workshops with practicing security analysts, we have developed a visualization approach inspired by the human process of contextualization; this system, called NUANCE, creates evolving behavioral models of network actors at organizational and regional levels, continuously monitors external textual information sources for themes that indicate security threats, and automatically determines if behavior indicative of those threats is present on a network.

Research Organization:
Pacific Northwest National Laboratory (PNNL), Richland, WA (US)
Sponsoring Organization:
USDOE
DOE Contract Number:
AC05-76RL01830
OSTI ID:
949135
Report Number(s):
PNNL-SA-57153
Country of Publication:
United States
Language:
English

Similar Records

Enhancing Network Visibility and Security through Tensor Analysis
Journal Article · Mon Feb 11 23:00:00 EST 2019 · Future Generations Computer Systems · OSTI ID:1501379

Data-Intensive Visual Analysis for Cyber Security
Book · Mon Jan 28 23:00:00 EST 2013 · OSTI ID:1081412

Real-World Cyber Security Demonstration for Networked Electric Drives
Journal Article · Tue Mar 11 20:00:00 EDT 2025 · IEEE Journal of Emerging and Selected Topics in Power Electronics · OSTI ID:3011825