New Visualization Requirements for Cyber Security
February 3, 2014, Electronic Imaging Conference, San Francisco—Pak Chung Wong from the Pacific Northwest National Laboratory talked about the need for new visualization tools for cyber security work. These tools differ from other visualization tools due to the requirements for rapid response and minimization of false positives and negatives.
To identify a requirements for cyber security visualization, they conducted seven interviews over five subject cases to define preferences and gaps in current practices. 11 questions related to: visualization help, daily data size, compute platform, data velocity, data sensitivity, the goal of visualization, the nature of the visualization, the role of visualization, data scope and acceleration, and the catchall category of what have you got and what do you want.
General preferences and gaps from the responses indicated that users want visualization capabilities, and ways to identify gaps in their systems. They would like to get better analytics capabilities to find the gaps, and would like to keep their favorite techniques in place. All of the users wanted help even though data sizes range from 100 bytes to terabytes.
Most users have apps in the cloud and on desktop machines. The key issues in data velocity were transient streams and issue-based postmortems. In terms of data sensitivity, the main comment was that they were given legal authorization. The goal for visualization work is to gain greater understanding of the issues, understand ongoing situations, and create better malware detection capabilities.
Because this relates to the intelligence community, the role of visualization is to refine executable graphs in classified apps. Although the users have some commercial tools, much is in government tools.
The gaps in their visualization tools are domain specific, but relate to interactive exploration to help look for unknowns. The temporal aspects of the data requires the use of multi-modal analysis and common timestamps across apps. Last, but not least is the desire to get interactive user interfaces. The tool designs are intended to improve situational awareness.
The techniques are multi-faceted and geographic, with data sizes mostly in the 100MB to 1GB range. The differences from other forms of visualization are the size and speed of the data. Much of the data sets are big and the post-mortem processing can involve TB of transactions. Their focus is on maps or clusters where they have limited visibility.
The data velocity includes full transient streams, partial streams with known issues, and 2-types of post-mortem. All of the users want full transient stream capabilities and the ability to process the data under an hour, with less than 15 minutes being an ideal target. Some of the smaller datasets can possibly be processed in real time.
In addition to the analytics, they need people. They all depend upon an analyst’s experience and expertise. Domain and context information are critical and users need to know the lay of the land. At times, they need to check payloads, because the art/craft/ intuition are very hard to replicate. The analysts still mostly use table browsing and text for their work. Excel spreadsheets and lists of items like IP addresses, data, time, to, from, and other metadata are all included in any analysis. Many analysts still use SQL database query, and it is hard to kill this practice.
Cyber security is a complex, multi-disciplinary activity and the visualization must accommodate a wide range of users and experiences. Some of the users are linguistic experts, cyber and topology experts, military, etc. The users need intuitive visualization, which is very different from just a good user interface.
The community has to address a 2-layer problem, the carrier and the payload. A threat may be inside a payload and very hard to find. This obfuscation may be deliberate, in encryption, stenography, etc. and due to the high volumes of data. Ideally, visualization will show who is talking to who, and what they are saying.
Another facet of the visualization is to change the volume of false positive and negatives. The volume and diversity of data can overwhelm the analyst, so it is incumbent on the tools to reduce the burden on the users and not just provide some answer to a query.
One aspect of this intelligence work is that malicious cyber activities tend to be repeated, so some kind based visualization is necessary. This allows the analyst to see repetitive patterns and reduce the data mass to only short time frames of interest. Outright attacks are rare, most are persistent.
In visualization, apology is less effective than some other techniques. Higher priorities go to traffic, temporal patterns, frequency, payload, etc. The graphic drawings are not the most prevailing cyber graphs because the visualization of the underlying data has a high degree of uncertainty. Cyber security information is dynamic, and volatile, and is never 100 percent visible. Sensors cannot capture and log all traffic so a correct visualization is not the same as the whole truth. The best you can hope for is a partial picture.
In addition to communications traffic, some of the users are also concerned about non-enterprise networks like SCADA. Executive or static visualization requires modeling, predictive analytics, and many other tools to be effective.


