{"id":"https://openalex.org/W2087449073","doi":"https://doi.org/10.1145/1850795.1850805","title":"Real-time visualization of network behaviors for situational awareness","display_name":"Real-time visualization of network behaviors for situational awareness","publication_year":2010,"publication_date":"2010-09-02","ids":{"openalex":"https://openalex.org/W2087449073","doi":"https://doi.org/10.1145/1850795.1850805","mag":"2087449073"},"language":"en","primary_location":{"id":"doi:10.1145/1850795.1850805","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1850795.1850805","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Seventh International Symposium on Visualization for Cyber Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5054038232","display_name":"Daniel M. Best","orcid":null},"institutions":[{"id":"https://openalex.org/I142606810","display_name":"Pacific Northwest National Laboratory","ror":"https://ror.org/05h992307","country_code":"US","type":"facility","lineage":["https://openalex.org/I1325736334","https://openalex.org/I1330989302","https://openalex.org/I142606810","https://openalex.org/I39565521"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Daniel M. Best","raw_affiliation_strings":["Pacific Northwest National Laboratory, Richland, WA","Pacific Northwest National Laboratory, Richland, WA#TAB#"],"affiliations":[{"raw_affiliation_string":"Pacific Northwest National Laboratory, Richland, WA","institution_ids":["https://openalex.org/I142606810"]},{"raw_affiliation_string":"Pacific Northwest National Laboratory, Richland, WA#TAB#","institution_ids":["https://openalex.org/I142606810"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5110192503","display_name":"Shawn Bohn","orcid":null},"institutions":[{"id":"https://openalex.org/I142606810","display_name":"Pacific Northwest National Laboratory","ror":"https://ror.org/05h992307","country_code":"US","type":"facility","lineage":["https://openalex.org/I1325736334","https://openalex.org/I1330989302","https://openalex.org/I142606810","https://openalex.org/I39565521"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Shawn Bohn","raw_affiliation_strings":["Pacific Northwest National Laboratory, Richland, WA","Pacific Northwest National Laboratory, Richland, WA#TAB#"],"affiliations":[{"raw_affiliation_string":"Pacific Northwest National Laboratory, Richland, WA","institution_ids":["https://openalex.org/I142606810"]},{"raw_affiliation_string":"Pacific Northwest National Laboratory, Richland, WA#TAB#","institution_ids":["https://openalex.org/I142606810"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5077308992","display_name":"Douglas V. Love","orcid":null},"institutions":[{"id":"https://openalex.org/I142606810","display_name":"Pacific Northwest National Laboratory","ror":"https://ror.org/05h992307","country_code":"US","type":"facility","lineage":["https://openalex.org/I1325736334","https://openalex.org/I1330989302","https://openalex.org/I142606810","https://openalex.org/I39565521"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Douglas Love","raw_affiliation_strings":["Pacific Northwest National Laboratory, Richland, WA","Pacific Northwest National Laboratory, Richland, WA#TAB#"],"affiliations":[{"raw_affiliation_string":"Pacific Northwest National Laboratory, Richland, WA","institution_ids":["https://openalex.org/I142606810"]},{"raw_affiliation_string":"Pacific Northwest National Laboratory, Richland, WA#TAB#","institution_ids":["https://openalex.org/I142606810"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5037398838","display_name":"Adam Wynne","orcid":null},"institutions":[{"id":"https://openalex.org/I142606810","display_name":"Pacific Northwest National Laboratory","ror":"https://ror.org/05h992307","country_code":"US","type":"facility","lineage":["https://openalex.org/I1325736334","https://openalex.org/I1330989302","https://openalex.org/I142606810","https://openalex.org/I39565521"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Adam Wynne","raw_affiliation_strings":["Pacific Northwest National Laboratory, Richland, WA","Pacific Northwest National Laboratory, Richland, WA#TAB#"],"affiliations":[{"raw_affiliation_string":"Pacific Northwest National Laboratory, Richland, WA","institution_ids":["https://openalex.org/I142606810"]},{"raw_affiliation_string":"Pacific Northwest National Laboratory, Richland, WA#TAB#","institution_ids":["https://openalex.org/I142606810"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5079291115","display_name":"William Pike","orcid":null},"institutions":[{"id":"https://openalex.org/I142606810","display_name":"Pacific Northwest National Laboratory","ror":"https://ror.org/05h992307","country_code":"US","type":"facility","lineage":["https://openalex.org/I1325736334","https://openalex.org/I1330989302","https://openalex.org/I142606810","https://openalex.org/I39565521"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"William A. Pike","raw_affiliation_strings":["Pacific Northwest National Laboratory, Richland, WA","Pacific Northwest National Laboratory, Richland, WA#TAB#"],"affiliations":[{"raw_affiliation_string":"Pacific Northwest National Laboratory, Richland, WA","institution_ids":["https://openalex.org/I142606810"]},{"raw_affiliation_string":"Pacific Northwest National Laboratory, Richland, WA#TAB#","institution_ids":["https://openalex.org/I142606810"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5054038232"],"corresponding_institution_ids":["https://openalex.org/I142606810"],"apc_list":null,"apc_paid":null,"fwci":5.0994,"has_fulltext":false,"cited_by_count":56,"citation_normalized_percentile":{"value":0.95937689,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"79","last_page":"90"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10799","display_name":"Data Visualization and Analytics","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10799","display_name":"Data Visualization and Analytics","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10064","display_name":"Complex Network Analysis Techniques","score":0.9879000186920166,"subfield":{"id":"https://openalex.org/subfields/3109","display_name":"Statistical and Nonlinear Physics"},"field":{"id":"https://openalex.org/fields/31","display_name":"Physics and Astronomy"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T13083","display_name":"Advanced Text Analysis Techniques","score":0.96670001745224,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/visualization","display_name":"Visualization","score":0.8276512622833252},{"id":"https://openalex.org/keywords/situation-awareness","display_name":"Situation awareness","score":0.7969266176223755},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7946538329124451},{"id":"https://openalex.org/keywords/visual-analytics","display_name":"Visual analytics","score":0.7053715586662292},{"id":"https://openalex.org/keywords/data-visualization","display_name":"Data visualization","score":0.5993676781654358},{"id":"https://openalex.org/keywords/pipeline","display_name":"Pipeline (software)","score":0.5514357089996338},{"id":"https://openalex.org/keywords/analytics","display_name":"Analytics","score":0.5194370746612549},{"id":"https://openalex.org/keywords/data-science","display_name":"Data science","score":0.5167107582092285},{"id":"https://openalex.org/keywords/abstraction","display_name":"Abstraction","score":0.4718126058578491},{"id":"https://openalex.org/keywords/human\u2013computer-interaction","display_name":"Human\u2013computer interaction","score":0.40390318632125854},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.26269349455833435},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.10568773746490479}],"concepts":[{"id":"https://openalex.org/C36464697","wikidata":"https://www.wikidata.org/wiki/Q451553","display_name":"Visualization","level":2,"score":0.8276512622833252},{"id":"https://openalex.org/C145804949","wikidata":"https://www.wikidata.org/wiki/Q478123","display_name":"Situation awareness","level":2,"score":0.7969266176223755},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7946538329124451},{"id":"https://openalex.org/C59732488","wikidata":"https://www.wikidata.org/wiki/Q2528440","display_name":"Visual analytics","level":3,"score":0.7053715586662292},{"id":"https://openalex.org/C172367668","wikidata":"https://www.wikidata.org/wiki/Q6504956","display_name":"Data visualization","level":3,"score":0.5993676781654358},{"id":"https://openalex.org/C43521106","wikidata":"https://www.wikidata.org/wiki/Q2165493","display_name":"Pipeline (software)","level":2,"score":0.5514357089996338},{"id":"https://openalex.org/C79158427","wikidata":"https://www.wikidata.org/wiki/Q485396","display_name":"Analytics","level":2,"score":0.5194370746612549},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.5167107582092285},{"id":"https://openalex.org/C124304363","wikidata":"https://www.wikidata.org/wiki/Q673661","display_name":"Abstraction","level":2,"score":0.4718126058578491},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.40390318632125854},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.26269349455833435},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.10568773746490479},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C146978453","wikidata":"https://www.wikidata.org/wiki/Q3798668","display_name":"Aerospace engineering","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/1850795.1850805","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1850795.1850805","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Seventh International Symposium on Visualization for Cyber Security","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":18,"referenced_works":["https://openalex.org/W61646295","https://openalex.org/W1529750112","https://openalex.org/W1647671624","https://openalex.org/W1810489654","https://openalex.org/W1984889142","https://openalex.org/W1989037929","https://openalex.org/W2047343660","https://openalex.org/W2049429007","https://openalex.org/W2068714596","https://openalex.org/W2097236039","https://openalex.org/W2100565272","https://openalex.org/W2105510466","https://openalex.org/W2111726016","https://openalex.org/W2113377603","https://openalex.org/W2126855459","https://openalex.org/W2132915272","https://openalex.org/W2139431384","https://openalex.org/W2171489309"],"related_works":["https://openalex.org/W2062940763","https://openalex.org/W2186032312","https://openalex.org/W3149127250","https://openalex.org/W2158984754","https://openalex.org/W2080934634","https://openalex.org/W4246764483","https://openalex.org/W2126824079","https://openalex.org/W2143428259","https://openalex.org/W2112083262","https://openalex.org/W4378086562"],"abstract_inverted_index":{"Plentiful,":[0],"complex,":[1],"and":[2,25,80,132],"dynamic":[3],"data":[4,39],"make":[5],"understanding":[6,91],"the":[7,42,112,117,152],"state":[8],"of":[9,44,48,55,77,92,141,154,160],"an":[10],"enterprise":[11],"network":[12,23,78,94,156],"difficult.":[13],"Although":[14],"visualization":[15,69,125],"can":[16,150],"help":[17,97],"analysts":[18,98,149],"understand":[19,151],"baseline":[20],"behaviors":[21],"in":[22,58],"traffic":[24],"identify":[26],"off-normal":[27],"events,":[28],"visual":[29],"analysis":[30,54,142],"systems":[31],"often":[32],"do":[33],"not":[34],"scale":[35],"well":[36],"to":[37,46,53,96,127,136,146],"operational":[38],"volumes":[40],"(in":[41],"hundreds":[43],"millions":[45],"billions":[47],"transactions":[49],"per":[50],"day)":[51],"nor":[52],"emergent":[56],"trends":[57],"real-time":[59,93],"data.":[60],"We":[61,103],"present":[62],"a":[63,81,128,138,155],"system":[64,88],"that":[65],"combines":[66],"multiple,":[67],"complementary":[68],"techniques":[70,107],"coupled":[71],"with":[72],"in-stream":[73],"analytics,":[74],"behavioral":[75],"modeling":[76],"actors,":[79],"high-throughput":[82],"processing":[83],"platform":[84],"called":[85],"MeDICi.":[86],"This":[87],"provides":[89],"situational":[90],"activity":[95],"take":[99],"proactive":[100],"response":[101],"steps.":[102],"have":[104],"developed":[105],"these":[106],"using":[108],"requirements":[109],"gathered":[110],"from":[111],"government":[113],"users":[114],"for":[115],"which":[116],"tools":[118,126],"are":[119],"being":[120],"developed.":[121],"By":[122],"linking":[123],"multiple":[124,158],"streaming":[129],"analytic":[130],"pipeline,":[131],"designing":[133],"each":[134],"tool":[135],"support":[137],"particular":[139],"kind":[140],"(from":[143],"high-level":[144],"awareness":[145],"detailed":[147],"investigation),":[148],"behavior":[153],"across":[157],"levels":[159],"abstraction.":[161]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":3},{"year":2021,"cited_by_count":8},{"year":2020,"cited_by_count":8},{"year":2019,"cited_by_count":3},{"year":2018,"cited_by_count":4},{"year":2017,"cited_by_count":2},{"year":2016,"cited_by_count":2},{"year":2015,"cited_by_count":3},{"year":2014,"cited_by_count":5},{"year":2013,"cited_by_count":8},{"year":2012,"cited_by_count":5}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
