计算机科学
可视化
视觉分析
组分(热力学)
形势意识
计算机安全
钥匙(锁)
网络安全
分析
信息可视化
数据科学
人工智能
工程类
热力学
物理
航空航天工程
作者
Kaitlyn DeValk,Niklas Elmqvist
标识
DOI:10.1177/14738716231189220
摘要
Real-time situation awareness is a key challenge of cybersecurity defense. Visual analytics has been utilized for this purpose, but existing tools tend to require detailed knowledge about the network, which can be challenging in large-scale, production networks. We conducted an interview study involving 24 security professionals to gather requirements for the design, development, and evaluation of visualization to aid situation awareness in cybersecurity. Using these findings, we designed a visualization tool – called RIVERSIDE – for providing a real-time view of the dynamically changing computer network to support situation awareness. We evaluated Riverside in a user study involving 10 participants. Participants were placed in an incident response scenario that tasked them to identify malicious activity on a network. 20% of the users identified all attack component, while an additional 40% only missed one component.
科研通智能强力驱动
Strongly Powered by AbleSci AI