Overview
Computer networks are growing larger and more complex as commercial and government entities have increasingly come to depend on the cyber infrastructure. Against this backdrop of increased complexity and reliance on the network infrastructure, the number of cyber attacks against critical cyber-infrastructure have also increased. The stakes have increased as well. The 2007 Russian cyber attack against Estonia hinted at the future of cyber warfare: coordinated bots can attack and cripple the cyber-infrastructure of a nation.
To combat this threat and others like it, the Secure Decisions division of Applied Visions Inc. has developed technologies for cyber defenders to facilitate the discovery, analysis and understanding of cyber attacks. This collaborative visual analytics platform, VIAssist, enhances Situational Awareness, facilitates collaboration and enables the analysis and understanding of cyber events. VIAssist links multiple visualizations into a multi-display system that enhances SA through multiple levels of visual analysis, from a high-level dashboard overview to powerful visualizations to the low-level textual details of cyber-related data. This enables analysts to view network and event data from multiple perspectives and levels of details.
A Cognitive Task Analysis (CTA) of cyber defenders in commercial and military environments helped in forging the system’s design; for example, motivating the collaborative and reporting functionality that differentiate VIAssist from other visualization systems. Based on the results of the CTA, we know that cyber defenders need to be able to understand the big picture, to answer questions they didn’t know they had, to put events into their larger context, to collaborate and generate hypotheses with other cyber defenders and to clearly and accurately report their hypothesis and findings. VIAssist provides an intuitive, customizable dashboard to provide a big picture view. Multiple visualizations are linked together to facilitate exploration and discovery. Different kinds of visualizations are provided to enable the analysis of events in network, temporal, and geographic contexts.
Collaboration is supported in multiple ways: through shared lists of critical and potentially malicious IP addresses, annotations, workspaces, and expressions. Embedded communication and reporting tools enable analysts to easily create and reuse templates that allow less-technical users to understand findings through the visualizations.
VIAssist was demonstrated at the 2006 Coalition Warrior Interoperability Demonstration, where it was named one of the “Top Technology Trials” for that important annual international military exercise.
VIAssist was built with support from the Department of Defense, Air Force Research Lab (AFRL) FireStarter program “Cyber Operations Technical Transition”, Contract# FA8750-10-C-0201.
Awards
VIAssist was a Long Island Science and Technology Network (LISTNet) 2007 Long Island Software Award (LISA) Best Software Product winner. VIAssist was recognized at annual awards banquet for excellence among Long-Island based software technology offerings.
Frequently Asked Questions
General Information
Data-related
VIAssist currently supports the analysis of a wide range of data sources and tools:
- Netflow data
- Netezza TwinFin
- Narus Insight
- Intrusion detection data
- Proprietary database formats
Secure Decisions will interface VIAssist functionality to other data sources to meet the needs of our users and the information security community. For a most up to date list of supported tools or custom development for specific applications, contact us at (631) 754-4920.
Users
VIAssist is a government-sponsored software application developed in close collaboration with government and commercial security professionals who use analytical tools and intrusion detection systems. Users include:
- Network Administrators
- Incident Response Teams
- Correlation & Threat Analysts
- Forensic Investigators
- Vulnerability Assessors
- CISOs and Commanders
Availability & Editions
System Requirements
No special hardware is needed to run VIAssist other than a typical PC (desktop or laptop). We currently recommend the following minimum system requirements to run VIAssist:
- 2.5 GHZ CPU or better
- 4 GB RAM or better
- Ethernet adaptor
- 1 GB disk space
VIAssist supports the following Windows Operating Systems:
- Windows XP Pro (With appropriate Service Packs applied)
- Windows Vista (With appropriate Service Packs applied)
- Windows 7 (With appropriate Service Packs applied)