Towards a Visual Analytics Workflow for Cybersecurity Simulations

Vit Rusnak, Martin Drasar

2023

Abstract

One of the contemporary grand challenges in cybersecurity research is designing and evaluating effective attack strategies on network infrastructures performed by autonomous agents. These attackers are developed and trained in simulated environments. While the simulation environments are maturing, their support for analyzing the simulation data remains limited, mainly to inspect individual simulation runs. Extending the analytical workflow to compare multiple runs and integrating visualizations could improve the design of both attack and defense strategies. Through our work, we want to spark interest in the largely overlooked domain of visual analytics for cybersecurity simulation workflows. In this paper, we a) analyze the current state of the art of using visualizations in cybersecurity simulations; b) conceptualize the three-tier analytical workflow and identify user tasks with suggested visualizations for each tier; c) demonstrate the use of visualizations that augment existing CYST simulator on several real-world tasks and discuss the limitations and lessons learned.

Download


Paper Citation


in Harvard Style

Rusnak V. and Drasar M. (2023). Towards a Visual Analytics Workflow for Cybersecurity Simulations. In Proceedings of the 18th International Joint Conference on Computer Vision, Imaging and Computer Graphics Theory and Applications (VISIGRAPP 2023) - Volume 3: IVAPP; ISBN 978-989-758-634-7, SciTePress, pages 179-186. DOI: 10.5220/0011695000003417


in Bibtex Style

@conference{ivapp23,
author={Vit Rusnak and Martin Drasar},
title={Towards a Visual Analytics Workflow for Cybersecurity Simulations},
booktitle={Proceedings of the 18th International Joint Conference on Computer Vision, Imaging and Computer Graphics Theory and Applications (VISIGRAPP 2023) - Volume 3: IVAPP},
year={2023},
pages={179-186},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0011695000003417},
isbn={978-989-758-634-7},
}


in EndNote Style

TY - CONF

JO - Proceedings of the 18th International Joint Conference on Computer Vision, Imaging and Computer Graphics Theory and Applications (VISIGRAPP 2023) - Volume 3: IVAPP
TI - Towards a Visual Analytics Workflow for Cybersecurity Simulations
SN - 978-989-758-634-7
AU - Rusnak V.
AU - Drasar M.
PY - 2023
SP - 179
EP - 186
DO - 10.5220/0011695000003417
PB - SciTePress