This paper describes the process of developing data visualisations to enhance a commercial software platform for combating insider threat, whose existing UI, while perfectly functional, was limited in its ability to allow analysts to easily spot the patterns and outliers that visualisation naturally reveals. We describe the design and development process, proceeding from initial tasks/requirements gathering, understanding the platform's data formats, the rationale behind the visualisation's design, and then refining the prototype through gathering feedback from representative domain experts who are also current users of the software. Through a number of example scenarios, we show that the visualisation can support the identified tasks and aid analysts in discovering and understanding potentially risky insider activity within a large user base.
翻译:本文描述开发数据可视化的过程,以加强一个打击内幕威胁的商业软件平台,因为现有的UI虽然功能良好,但是其使分析家能够容易地发现可视化自然揭示的模式和外部线的能力有限。我们描述设计和开发过程,从最初的任务/需求收集开始,了解平台的数据格式,了解可视化设计背后的理由,然后通过收集同时也是软件当前用户的有代表性的域专家的反馈来完善原型。我们通过一些实例,表明可视化可以支持确定的任务,并帮助分析家在大型用户基础内发现和了解潜在风险的内部活动。