Company
Date Published
Author
Steven Noel
Word count
1148
Language
English
Hacker News points
None

Summary

The development of CyGraph, a tool for cyber warfare analytics, visualization, and knowledge management, aims to address the challenges of information overload in security analytics. This tool brings together isolated data and events into an ongoing overall picture for decision support and situational awareness, prioritizing exposed vulnerabilities mapped to potential threats in the context of mission-critical assets. CyGraph incorporates an attack-graph model that maps the potential attack paths through a network, including various network attributes that potentially contribute to attack success. The dynamically evolving attack graph provides context for reacting appropriately to attacks and protecting mission-critical assets. Leveraging Big Data Architecture, CyGraph uses a flexible property-graph formulation implemented in Neo4j, a NoSQL database optimized for graphs, to model schema evolution with available data sources and desired analytics. This approach enables the creation of additional nodes, relationships, and properties without requiring schema changes or other database renormalizing. With its comprehensive knowledge base, CyGraph provides insight into mission impact, including potential attack-pattern relationships that fill in gaps between known vulnerabilities and threat indicators.