Quote from Rob Neyer, ESPN

"In business, as in baseball, the question isn't whether or not you'll jump into analytics; the question is when. Do you want to ride the analytics horse to profitability...or follow it with a shovel?"

Friday, December 14, 2007

WebTAS 3.0

Here is some cool software for visualizing events over a timeline. The U.S. Military has used this for mission planning for a few years. It came from an older system called TAS (Temporal Analysis System)

According to their website:

WebTAS is a modular software toolset that supports fusion of large amounts of disparate data sets, visualization, project organization and management, pattern analysis and activity prediction, and various presentation aids.

These tools have been successfully used by many Federal and regional government organizations, and is ideally suited to distributed networks and intranets.

WebTAS provides an integrated toolbox to users needing to make sense of large and diverse sets of data. The capabilities bundled in this environment include:
  • Bringing together multiple sources of data into common, fused pictures
  • Sophisticated visualization components for viewing data
  • Ad-HOC query of disparate data
  • Trend and pattern detection
  • Dynamic web content generation based on these data sources
  • Easily configured domain customization

WebTAS History

WebTAS is the result of the evolution of the Temporal Analysis System (TAS) in effort to satisfy user requirements for the U.S. intelligence community. WebTAS was developed by AFRL to assist intelligence analysts with the comprehension of large amounts of information.

The TAS program was first formulated in 1988 in an effort to relieve analysts from time-consuming manual techniques. The goal was to provide intelligence analysts with tools to build and maintain event activity timelines and to observe and discover behaioral patterns via data query and visualization techniques. Once behavioral patterns are identified and modeled, WebTAS can automatically search for data, in near real-time, that matches model or models, and then alert users to these situations of interest. Based on information described in the models, WebTAS can also compute predictions of future activity.

WebTAS functionality has expanded to include more generalized features, including data representation, data access to a variety of diverse data sources, data visualization, easy-to-use user interfaces, web-based functions, extensible and pluggable interfaces, etc. WebTAS is an integration platform that has been used on many other programs.

WebTAS deployment has also expanded drastically. In addition to the intelligence community, WebTAS is now used in command and control, resource planning, drug interdicition, counter-intelligence, counter-terrorism, special operations planning, maritime suveillance, computer network defense, and many other application areas and problem domains.


WebTAS Overview
WebTAS Training
WebTAS Downloads
WebTAS White Paper

CRM Collaboration Firm SPSS Notes MarketBridge

MarketBridge, a vendor of sales and marketing services, has announced it was named SPSS (News - Alert) Systems Integrator Partner of the Year 2007 at the annual SPSS Directions User Conference in Orlando.

MarketBridge took home the Systems Integrator honor for developing joint products with SPSS, a vendor of predictive analytics software, to solve such marketing and sales problems as marketing mix optimization, improving B2B pipeline performance and leveraging "passive" market research techniques to estimate the attitudinal effects of marketing activities.

To read the Marketing Sciences white paper, ''Putting the Relationship Back in Relationship Marketing,'' detailing methods such as predictive analytics for building Relationship Marketing programs click on this link: http://www.market-bridge.com/Forms2/Relationship_Marketing.html. This summer MarketBridge (News - Alert) and SPSS formed a partnership to develop and implement marketing and sales products.

MarketBridge delivers the marketing and sales optimization side of things, customizing and installing customers' marketing analytics applications, while SPSS has the platform required to satisfy the complexity of a multi-channel marketing model.

Using SPSS' Predictive Enterprise architecture, MarketBridge has implemented a "collaborative CRM" program for a computer hardware vendor, allowing channel partners to "take advantage of the power of analytics and OEM data to build, deploy and measure campaigns," MarketBridge officials say. The partnership is being driven by the development of joint products designed to solve several marketing and sales problems, including marketing mix optimization, improving B2B pipeline performance and using passive market research techniques to estimate the attitudinal effects of marketing activities.

"For the last 15 years, MarketBridge has been increasingly focused on using analytics," says Andy Hasselwander, Vice President of Marketing Sciences. "SPSS' suite of predictive analytics products is a natural fit, for both our internal project work and for deployment within client environments."

Patrick McCue, Vice President of Worldwide Alliances for SPSS, said embedding SPSS technology inside of MarketBridge's pay-for-performance execution programs "has allowed MarketBridge to attain peak levels of performance by using predictive analytics."

Thursday, December 13, 2007

Attack Tree Models

An attack tree model is a graphical representation of the possible paths or ways in which an asset can be attacked. Nodes are shown in Attack Tree Models as geometric objects like boxes, polyhedrons, etc. In an attack tree, these nodes represent goals or states that an attacker wishes to achieve.

The Root node resides at the top of the tree, and represents the overall goal of the attacker. The attacker's goals will vary depending on the type of asset being analyzed and may be broad or narrow depending on the attacker’s purpose. Examples of root goals might include: Steal company assets; Destroy a building; Damage reputation.

The attacker’s overall goal is then broken down into increasingly detailed subgoals. The Analyst gains insights by decomposing the higher-level parent goals into the lower goals that the attacker must achieve in order to prevail.

Nodes below a particular node represent subtasks and are referred to as children and the nodes above any particular node are referred to as parent nodes. Nodes two levels above are called grandparents and so on.

Risk Theory

How much security do we need? Just enough so that Security is Commensurate with Risk. What most people want when they ask for a “secure” system is one in which the level of risk is acceptable. To understand what is meant by this it is first necessary to understand the meaning of risk.

Risk (of a particular event) / Event Probability × Resulting Damage

This formula is used, with slight variations, in many fields. It is often expressed as an Annualized Loss Expectancy (ALE) in $/year. In theory, it should be easy to determine the risk of a particular type of event. All that is needed is to find out how likely it is that the event will occur and how much damage it will cause. While it is usually straightforward to estimate the impact of an incident, coming up with a figure for Event Probability is more difficult.

The probability of simple events(such as tossing a coin or rolling dice) can be determined using common mathematical principles. Real world situations are seldom this simple so this approach must be judiciously applied.

Wednesday, December 12, 2007

Adversary Path Diagrams or ASDs

A little something from the Department of Energy.

Sandia National Laboratories, of Albuquerque NM was assigned by the United States Department of Energy (DOE) as the lead laboratory for physical security research and development during the mid-1970’s. This initiative was intended to aid in the protection of nuclear weapons from theft or sabotage. As a part of this responsibility, Sandia developed Cost and Performance Analysis (CPA). CPA provides actionable information on the cost and effectiveness of DOE security systems.

This strategy was an integration of two existing PC-based software tools:

· ACEIT (Automated Cost Estimating Integrated Tools) developed by Tecolote Research Inc. for the U.S. Air Force. ACEIT is widely used throughout the Department of Defense (DOD). ACEIT supports costs analysis over the full life-cycle of a system;

· ASSESS (Analytic System and Software for Evaluating Safeguards and Security) developed jointly by Lawrence Livermore National Laboratories and Sandia National Laboratories for the DOE. ASSESS supports performance analysis.

CPA organizes the cost and performance data generated by ACEIT and ASSESS into Excel spreadsheets. These spreadsheets make the data more accessible to analysts and organizes the results for management.

ASSESS models the protective domain visually, and maps out Adversary Sequence Diagrams. The Adversary Sequence Diagram (ASD) is a graphical representation of physical protection system elements along paths that adversaries can follow to accomplish their objective. For a specific physical protection system and threat, the most vulnerable path can be determined.

This path with the least physical protection system effectiveness establishes the effectiveness of the total physical protection system. An ASD is developed for a single critical asset associated with an undesired event.

Modeling 7: More Complex Models

Markov chains, queuing theory, inventory theory, decision analysis and simulation are examples of probabilistic models useful to analytical loss prevention and analysis. A Markov chain consists of a set of sequential stochastic events that are independent of each other.

An example of a Markov Chain could be a typical alarm response. A specific alarm may or may not activate; if it does, it may or may not be a false alarm; if it is an actual alarm, force may or may not be required; if force is used, it may or may not be deadly physical force.

Based on this chain, the probability that deadly force will be required for any given alarm activation can be estimated. Queuing Theory and inventory theory focus on moving things or people (entities) through a system. They can help to answer questions like, “How long can I expect screening facility lines to be?” or “Where are the Risk Points of Failure in my Package Delivery Process” or “How many widgets do I need to keep in stock?”

Most of these techniques are complementary. In fact, most complex systems and issues require a combination of these tools if planners are to understand the interrelationships fully and work them toward an optimal solution.

Linear Programming is a deterministic, mathematical, problem-solving technique. It is used optimize a specific goal, such as minimizing cost or maximizing profit.

Monte Carlo simulation is commonly used in Risk Analysis, a technique for applying probability theory to business problems to build probabilistic models. We will demonstrate a fairly complex risk-based Security and Loss Prevention model later in this blog. These models enable Loss Prevention and Security management to make decisions under uncertainty (such as how should I deploy my staff and budget to minimize risk).

Simulation and role playing are most useful in decision-making when:

· The environment is changing.
· There are conflicts among the people involved.
· There is little accurate data on the intentions of the relevant people.
· The decision is important.

Sounds perfectly suited for use by Loss Prevention and Security Professionals doesn’t it?

Modeling 6: Deterministic Vs Probalistic Models

There are two categories of mathematical models used to describe security and loss prevention systems and environments – deterministic and probabilistic (also known as stochastic). The gravitational formula described in the last posting is an example of a deterministic model. This relationship between falling bodies and gravitational pull never varies regardless of circumstance – it is always the same. The size of a parachute adequate to reduce the velocity of a falling parachutist to acceptable limits can be determined using the deterministic gravitational formula, and the analysis of this phenomenon is called parametric analysis. The model is completely predictable.

Unpredictable systems have an element of uncertainty (risk) associated with them. That “normal (20,5)” access control point makes an excellent example. If the loss prevention or security practitioner were to make random, one-minute counts of traffic through that point, the individual counts would not likely consist of all 20’s (always counting 20 people per minute in each and every count). Using stochastic modeling, however, we can make intelligent and accurate predictions about the most likely capacity range of the access control point based on the known distribution information. By combining this information with the facility population, we can make very dependable decisions regarding the access control point (is it adequate, or does it pose a potentially hazardous bottleneck, etc.).

For solving problems in which we are certain of the relationships that are present within a system or process that is important to our operations, we can use linear and nonlinear programming, goal programming, network analysis and deterministic dynamic programming techniques. These are very useful tools for measuring stochastic systems because deterministic models are normally more simple and easier to manipulate than probabilistic models.

By judiciously assuming away the uncertainties in a system, we can usually identify the parts (attributes) of the system that have the greatest influence over its operation. This process focuses a problem and allows for more effective analysis of a stochastic system.