Personal tools
You are here: Home pubs VizSec 2007 Proceedings The Real Work of Computer Network Defense Analysts
Document Actions

A D'Amico and K Whitley (2008)

The Real Work of Computer Network Defense Analysts

In: VizSEC 2007: Proceedings of the Workshop on Visualization for Computer Security, Date-Added = 2008-06-24 09:46:43 -0400, Date-Modified = 2008-06-24 09:46:52 -0400, edited by Goodall, J. R. and Conti, G. and Ma, K. L.. Springer, pages 19-37.

This paper reports on investigations of how computer network defense (CND) analysts conduct their analysis on a day-to-day basis and discusses the implications of these cognitive requirements for designing effective CND visualizations. The supporting data come from a cognitive task analysis (CTA) conducted to baseline the state of the practice in the U.S. Department of Defense CND community. The CTA collected data from CND analysts about their analytic goals, workflow, tasks, types of decisions made, data sources used to make those decisions, cognitive demands, tools used and the biggest challenges that they face. The effort focused on understanding how CND analysts inspect raw data and build their comprehension into a diagnosis or decision, especially in cases requiring data fusion and correlation across multiple data sources. This paper covers three of the findings from the CND CTA: (1) the hierarchy of data created as the analytical process transforms data into security situation awareness; (2) the definition and description of different CND analysis roles; and (3) the workflow that analysts and analytical organizations engage in to produce analytic conclusions.
10.1007/978-3-540-78243-8_2
 
by John Goodall last modified 2008-06-24 05:50
Log in


Forgot your password?
New user?
related from amazon
Navigation
 
Sponsored by

google search
Google
advertisements
 

Powered by Plone CMS, the Open Source Content Management System

This site conforms to the following standards: