Automatic Narrative Summarization for Visualizing Cyber Security Logs and Incident Reports
Robert Gove
Abstract
Visualization of a summarized incident report Fig. 1. Visualization of an incident report (top) and a summary of the incident report (bottom). (Screenshots do not show real data.)
Incident reports that include dozens of entities and hundreds of relationships benefit from this compact visualization because a table shows one row for each relationship or event. By using a summary of the incident report, this visualization can be even more compact and focus analyst attention on the core sequence of events and the relationships between the main victims and attackers.
Abstract-Cyber security logs and incident reports describe a narrative, but in practice analysts view the data in tables where it can be difficult to follow the narrative. Narrative visualizations are useful, but common examples use a summarized narrative instead of the full story's narrative; it is unclear how to automatically generate these summaries. This paper presents (1) a narrative summarization algorithm to reduce the size and complexity of cyber security narratives with a user-customizable summarization level, and (2) a narrative visualization tailored for incident reports and network logs. An evaluation on real incident reports shows that the summarization algorithm reduces false positives and improves average precision by 41% while reducing average incident report size up to 79%. Together, the visualization and summarization algorithm generate compact representations of cyber narratives that earned praise from a SOC analyst. We further demonstrate that the summarization algorithm can apply to other types of dynamic graphs by automatically generating a summary of the Les Mis érables character interaction graph. We find that the list of main characters in the automatically generated summary has substantial agreement with human-generated summaries. A version of this paper, data, and code is freely available at https://osf.io/ekzbp/.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext eb9f5bc2-06a6-4d6f-850f-4ceb7a16d1abCited by top-tier papers2
- Character-Oriented Design for Visual Data StorytellingKeshav Dasu, Yun-Hsin Kuo, Kwan-Liu MaIEEE VIS 2023 · 17 citations
- The Influence of Visual Provenance Representations on Strategies in a Collaborative Hand-off Data Analysis ScenarioJeremy E. Block, Shaghayegh Esmaeili, Eric D. Ragan, John R. Goodall et al.IEEE VIS 2022 · 7 citations
Builds on1
Related papers
- Narrative Maps: An Algorithmic Approach to Represent and Extract Information NarrativesBrian Keith Norambuena, Tanushree MitraCSCW 2020 · 26 citations
- ATLAS: A Sequence-based Learning Approach for Attack InvestigationAbdulellah Alsaheel, Yuhong Nan, Shiqing Ma, Le Yu et al.USENIX Security 2021 · 256 citations
- DEPCOMM: Graph Summarization on System Audit Logs for Attack InvestigationZhiqiang Xu, Pengcheng Fang, Changlin Liu, Xusheng Xiao et al.S&P 2022 · 88 citations
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- GARNET: GoT-Based Alert Reduction and Narrative Event TracingYiru Gong, Song Liu, Changzhi Zhao, Junrong Liu et al.AAAI 2026
