Full Program »
A Tool To Support The Investigation and Visualization of Cyber And/or Physical Incidents
Investigating in an efficient way the information collected from a system’s ac-tivity can help to timely detect malicious attempts and to better understand the context behind past incident occurrences. Nowadays, several solutions can be used to monitor system activities with the objective of detecting probable ab-normalities and malfunctions, however, most of these systems overwhelm their users with huge amounts of information making it harder for them to perceive incident occurrences and their context. Our approach combines a dynamic and intuitive user interface with Machine Learning forecasts in order to provide an intelligent investigation tool that facilitates the security operator’s work. Our system is also able to act as an enhanced and fully automated decision support mechanism that provides suggestions about possible incident occurrences.