Helping intelligence analysts detect threats in overflowing, changing and incomplete information
Jérôme Thoméré, Ian W. Harrison, John D. Lowrance, Andrés Rodríguez, Enrique H. Ruspini, M. Wolverton · 2004
An important role of intelligence organizations is to be able to identify and predict threats within a vast quantity of imprecise and noisy information. We describe the concept and function of our pattern-matching architecture, LAW (Link Analysis Workbench). This system is based upon two main ideas. The first idea is that both the data and the threats can be described in term of graphs of entities and events linked together with semantic relationships. Therefore, graph-based pattern matching techniques can be used to identify threats. The second idea is that analysts constitute an essential part of the system; LAW is designed to handle a lot of interaction with the user, particularly to help in authoring and revising patterns, by allowing analysts to understand the matching process and results.