Professional Documents
Culture Documents
I2 Inteligence Analyst's Notebook
I2 Inteligence Analyst's Notebook
White Paper
Contents comprehensive range of visual analysis tools help users build insight
and understanding on complex data sets. It helps drive the faster
2 Introduction discovery of key individuals, connections, relationships, events,
3 Who should read this white paper patterns and trends in data that might otherwise be missed.
Integrated Social Network Analysis capabilities also deliver
3 Potential benefits of i2 Analyst’s Notebook increased comprehension of social relationships and structures
5 Key features of i2 Analyst’s Notebook within networks of interest.
23 Technical description The results that are delivered from this detailed analysis can
then be shared with intuitive and visual briefing charts or
23 What prerequisites are required to install the product?
visualizations. These simple visualizations can easily be
23 What documentation is provided? included in other end intelligence products. This greatly
simplifies the communication of sometimes complex
23 For more information
information and scenarios and ultimately helps to drive more
timely and accurate operational decision making.
Identify connections, patterns, and key intelligence Rapid deployment delivers near-immediate
that might otherwise be missed productivity gains
• Identify the key who, why, what, where and when of any • Remove the need for professional services deployment
analysis question with a wide range of visual analysis tools costs with wizard-driven installer
• Combine association, temporal and geospatial aspects of data • Reduce the time to streamline analysis and end intelligence
with multi-dimensional analysis views product generation activities with rapid deployment of
• Quickly highlight key individuals and relationships and their powerful visual analysis capabilities
connections to key events with core link analysis capabilities • Rapid deployment and intuitive, modern user experience
• Understand critical timeline of events or patterns within delivers near immediate productivity gains
criminal activities with powerful temporal analysis tools
• Identify potentially important intermediaries between Proven worldwide visual analysis solution
• Over 2,000 organizations worldwide have used this
seemingly unconnected entities in a network
intelligence analysis solution
Increase understanding of complex criminal, terrorist, • Designed with input garnered from customer experiences
and fraudulent networks collected in real operational environments
• Gain better insight and understanding of the structure, • Comprehensive support infrastructure for global organizations
hierarchy and ‘modus-operandi’ of complex networks with with language versions available in 17 languages
integrated Social Network Analysis tools
• Aid the decision-making process and ensure best resource Key features of i2 Analyst’s Notebook
utilization for operational activities in network disruption,
surveillance or influencing Overview
i2 Analyst’s Notebook is a powerful visual analysis environment
Simplify the communication of complex information that offers users a comprehensive range of capabilities to
to support timely and accurate decision making identify actionable intelligence hidden within disparate data
• Clearly communicate complex data and scenarios with sets. These capabilities include:
intuitive and easy-to-follow charts and visualizations
• Drive the effective and efficient sharing of intelligence • Flexible data acquisition tools to quickly ingest a wide
for internal teams and across intelligence organizations variety of data types and formats
• Effectively share intelligence with a familiar tool that over • Flexible data modeling and visualization environment that
2,000 organizations use does not constrain the input of complex relational data
• Powerful range of visual analysis capabilities that enables
users to quickly gain increased understanding and reduces
the time to pin-point key intelligence
• Effective dissemination tools that simplify the communication
of complex data and scenarios
IBM Security 5
Drag and drop manual data entry This visual interface in i2 Analyst’s Notebook displays the wide
i2 Analyst’s Notebook includes manual data entry options that range of icon, link, and attribute types available to users. This
are designed to allow rapid chart item creation and editing. This extensive range can be used to best represent the imported data
function provides an intuitive drag and drop interface that helps and allows users to quickly add the wanted information on to a
to quickly build chart data. Users are able to choose from the chart. Templates that can be tailored to a user’s data entry
extensive array of icon types to visually represent real-world requirements can also be created.
items or events.
Other importing methods
i2 Analyst’s Notebook also offers the ability to import data in
XML format. Style sheets can be created that are used in the
import process to transform the data into the format that is
required for i2 Analyst’s Notebook.
This smooth integration gives analysts the ability to retrieve Flexible data model and representation
and analyze information that is stored in multiple, standard i2 Analyst’s Notebook provides users with an environment
relational databases. With live data access, analysts can use that offers flexibility in how data is modeled. The flexibility is
designed to ensure that users are not constrained in the input
i2 Analyst’s Notebook to quickly retrieve vital information from of complex relational data. The intuitive environment allows
key databases. Users are also assured that any analysis is based data to be modeled in various ways. Information can be
on the most up-to-date information available. It also helps displayed in the most effective manner to suit the type of
remove any reliance on a database specialist or the need to data to be viewed and the analysis to be performed.
learn a complex query language.
This flexibility allows users to:
Organizations can also create data connections to existing data
• Represent information to best suit the data to be analyzed
sources themselves by using the IBM i2 Analyst’s Notebook SDK.
• View data in multiple ways in the form of network and
timeline views
i2 Analyst’s Notebook can be upgraded to • Effectively visualize a wide range of data sets
allow connectivity to one or more of your • Perform various tasks for both analysis and briefing purposes
existing data sources. The visualization environment within i2 Analyst’s Notebook
allows users to represent information in association or timeline
charts. Items can be represented as entities, links, events,
timelines or attributes in order to best present the type of data
to be analyzed. This helps drive the effective analysis and
visualization of a wide range of data sets. Examples include
social networks, telephone records, financial transactions and
internet traffic records, to name but a few.
8 IBM i2 Analyst’s Notebook
Association charting/Link analysis The link analysis environment in i2 Analyst’s Notebook allows
Link analysis, the bedrock of i2 Analyst’s Notebook since its users to display their data in association charts. The association
inception, is a proven tool for intelligence analysts. It remains a view can be used to show the relationships between entities
key ingredient in identifying key connections and relationships such as people and organizations and illustrate how they are
within complex data. The extensive association visualization and interconnected. A wide range of formatting options allows
analysis tools in i2 Analyst’s Notebook help users in identifying users to quickly and easily represent real-world information.
key aspects within a data set of interest such as: These extensive options help provide increased insight and
understanding of a wide variety of ‘networks’. It helps analysts
• Key individuals and their relationships with others better understand the relationships within criminal networks,
• Structures in networks the communication patterns between individuals in a network,
• Close-knit groups of individuals (clusters) and how money flows across a network and much more.
• Information or commodity flow across a network
Timeline charting
i2 Analyst’s Notebook goes beyond just how entities are
interconnected by also allowing information to be portrayed in
the form of timeline charts. These temporal views can be used
to illustrate how sequences of events unfold over time.
They help not only reveal the interactions between entities but
also portray when these interactions occur.
IBM Security 9
Timeline charts are commonly used to analyze information such • Items can also be graded to record information such as source,
as telephone call records and any forms of communications or reliability and clearance level. The grading structure is
financial transactions. They also enable users to build a picture configurable to suit the needs of an organization.
of a sequence of events for time periods of interest. These type • Items that are imported from external data sources can also
of charts provide a powerful visualization that help to simplify return the property information on those items in the form
both the analysis and briefing of key temporal information. of data records. This rich data can then be used by many of
the analysis tools within i2 Analyst’s Notebook.
Item property model
Users can easily use the following methods to store properties Item visualization/Formatting
or supplemental information for an item within i2 Analyst’s i2 Analyst’s Notebook provides an extensive icon set with a
Notebook: high-quality, ultra-modern 3D look that offers clear, modern
and detailed real-world representations in charts. The extensive
• An item’s type is an important property. The type property is range of icons that are provided includes individual sets that are
used to define both entity and link types in a chart. In the targeted at specific sectors. These icon sets include Defense,
case of entities, the type can be used to define the visual icon Cyber, Telephone and Financial / Fraud analysis to name a few.
style that is displayed in the chart.
• Semantic types can be applied to give real-world meaning Users are also provided with many formatting options. These
for an item type. The real-world meaning helps when options help in the identification of key information during
performing a search on a data set. For example, a search for analysis or for emphasizing important items when briefing
a person type returns both males and females in the results. intelligence. The formatting options available in i2 Analyst’s
• Other item properties can be stored as attributes against Notebook include the ability to:
an item.
• i2 Analyst’s Notebook includes a wide range of entity • Apply color icons to visually represent real-world properties
(including associated visual icons), link, and attribute types. of an entity, such as the color of a vehicle.
However, users can easily create and add their own. • Visually categorize items in the form of colored Icon
• Users (or their organization) can create templates so that Frames that can be used to visually group items with common
users are only given the option to choose types that are most properties. These Icon Frames can also be used
commonly used. Organizations can standardize the way to visually display analysis results from tools such as Social
information is entered across an entire organization. Network Analysis.
• An image — for example mug shots or CCTV imagery — can • Modify the size of entities to identify or emphasize key or
also be stored against an entity. These images can then be important entities within a data set
used to display on the chart in place of an entity’s visual icon. • Include other supporting data such as pictures to enhance
• Supplemental information — that is, extra information on an briefing charts or reports with images of individuals. Timeline
item from a different source — can be added in the form of charts can also be enhanced to include event
cards. These cards provide a method to record text-based frames that depict, for example, CCTV images of an event.
information against an item while also recording the source.
10 IBM i2 Analyst’s Notebook
• Display the direction of links to visually represent who called Conditional formatting
who within a phone call or how money flows Any formatting can also be applied semi-automatically with the
between accounts use of i2 Analyst’s Notebook Conditional Formatting. Users can
• Categorize links with the use of color, width, or link define a set of rules that automate the process of formatting
style. Easily identify differing types of relationship, higher chart data to emphasize significant information for analysis or
volumes of calls between individuals, relative size of financial presentation purposes. Rules can also be saved so that repetitive
transactions between accounts, or the confidence level of tasks that are required across many charts can be automated.
information that links two people together.
• Group items within a chart to ensure that items can be Multiple rules can be set up in conditional formatting
selected and moved together as a group either manually specifications to perform complex formatting tasks. These
or when a user runs one of the analytical layouts. rules can be configured to work against the properties that are
• Change the display status of an item. Items can be hidden contained within chart entities, links and attributes. As with
(the item still exists but is not displayed) or “grayed-out” so import specifications, the conditional formatting specifications
they are de-emphasized compared to other chart items. can be saved either locally or in a workgroup. Organizations
Users can then put emphasis on particular items in a chart are provided with an effective method of standardizing analysis
but still maintain their context within a wider network. and briefing tasks across wider teams. These specifications
can be shared to standardize the techniques that are used for
both analysis and presentation purposes. Examples include
identification of important information in the analysis phase,
or for standardizing the format of charts for reporting and
presentation purposes.
• Quickly analyze data by providing multiple analytical information of relevance. Any non-relevant information that
views on data of interest does not pass the filter criteria can be filtered out by either
• Drill down into data sets to identify non-obvious hiding it or ‘graying’ it out. Multiple filters can also be applied
connections, patterns, and trends to quickly and efficiently narrow down larger data sets and
• Get better insight into the critical timeline of events. identify possible high-value intelligence.
• Identify potentially important intermediaries between
seemingly unconnected entities in a network
• Increase understanding of target criminal, terrorist,
or fraudulent networks
• Identify potential duplicates within imported data.
• Understand the who, what, when, where and why of
any analysis task
Users can perform a more detailed analysis of a data set with This understanding can help users to quickly identify patterns
interactive histogram view. Data can be viewed at a more granular in activity or aspects of a target’s likely pattern of life. It also
level — for example, show by days instead of months. helps identify how and when a target individual works or
It can also display the data for a selected range only —for example, whether there are any regular patterns in terms of their
show only the items in June. common activities.
The histogram view also works interactively with the main The heat matrix view, in the same way as the histogram view,
chart view. Data that falls outside the selected time period works interactively with the main chart view.
within the histogram can be hidden or ‘grayed-out’ within the
chart. Users can then display both association information Social network analysis
within the main chart and temporal information within the i2 Analyst’s Notebook provides analysts with the means to
histogram simultaneously. This combination is designed increase understanding of the structure, hierarchy and modus
to help users to gain better insight into how, over time, operandi of criminal and terrorist networks.
communications occur between individuals or how finances
might flow across a network. Social network analysis (SNA) has emerged as an effective
intelligence analysis technique. It enables the analysis of how
Heat matrix view — The heat matrix takes the temporal and why social groups operate, interact and behave in particular
analysis of a charted data set a step further. It offers a more ways. This quantitative technique enables users to map and
detailed breakdown of the temporal content of data, allowing measure complex networks of entities such as people and
users to map and visualize activities against two temporal ranges. organizations, by measuring the interactions between them.
This capability helps to provide a much quicker answer to
temporal questions — do activities happen at a certain time of SNA techniques can help analysts gain better insight and
day AND a particular day of the week? understanding of complex networks by providing users with
insight into aspects of social structure and sources and distribution
of power of a network. This can shed critical insight on the
intricacies of a network, highlighting who knows whom and who
does business with whom. By monitoring the communication
patterns between network nodes, the network’s structure can be
established, which then enables identification
of critical nodes and their relationships.
SNA techniques can also help give insights into the performance
of a network as a whole and its ability to achieve its key
goals. It helps to identify characteristics of a network that
normally are not immediately obvious, such as the existence
of smaller subnetworks that operate within a larger group.
The relationships between prominent people of interest who
IBM Security 15
wield the greatest influence over the rest of the network can be The SNA centrality measures that are included in i2 Analyst’s
understood better. SNA also helps identify how directly and Notebook are:
quickly information flows between people in different parts of the
network. Degree centrality — Identifies entities who are the most
active in a network that is based on the number of direct links
Using SNA measures can help analysts to understand individuals’ to other entities
roles within a network. Coupled with the temporal analysis
capabilities within i2 Analyst’s Notebook, SNA can help identify Closeness centrality — Identifies entities who have the best
so-called emerging leaders and rising stars. These individuals are access to other parts of a network and visibility of activities
people who increase in importance or influence within a network within the rest of a network
over time.
Betweenness centrality — Identifies entities who act as
Better understanding of a network, its structure, hierarchy, and gatekeepers or bridges of information and control information
individuals’ roles within a network is vitally important. This flow between different parts of a network
understanding helps drive better operational decision making
whether for network disruption, surveillance, or information Eigenvector centrality — Identifies how well-connected an
access and dissemination purposes. entity is and how much direct influence it has over the most
active entities in the network
This mapping file format can be imported in to other common More information on the benefits and capabilities of this
mapping applications. offering can be found in the i2 Analyst’s Notebook Connector
for Esri Product Overview white paper. This white paper is
Analyst’s Notebook Connector for Esri — i2 Analyst’s available at ibm.com/i2software
Notebook Connector for Esri is an optional plug-in to i2
Analyst’s Notebook. It enables users to combine the link and Entity matching
temporal analysis capabilities of i2 Analyst’s Notebook with the With the ability to take data from a wide variety of sources it
geospatial capabilities provided by an available Esri ArcGIS becomes important to identify, and utilize items from different
Server. This powerful combination allows users to connect to data sources that are in fact the same real-world object. Entity
and utilize available Esri geospatial analysis services. These matching, within i2 Analyst’s Notebook, is the process of finding
services include base maps, dynamic map feature layers, and occurrences of items on a chart that represent the same item. i2
analytical services such as Geocoding, Find Route, and Analyst’s Notebook provides two types of
Drive-time analysis. entity matching:
This closely coupled, two-way integration allows users to Automatic entity matching — i2 Analyst’s Notebook
create a geospatial view directly inter-connected with the automatically detects entities that are the same as other entities
association and temporal views of i2 Analyst’s Notebook. as they are being imported into a chart. This matching works
It allows users to perform the who, what, when and where on item identity or database identity. The identities of two
analysis all from within a single combined environment. entities are deemed to be the same if they match exactly and
are the same case character for character. Because two identical
entities are not allowed to coexist on the same chart, i2
Analyst’s Notebook merges them together, even if their labels
are not the same.
Infotips — Any top-level item in i2 Analyst’s Notebook can hold Visual Search — Visual Search provides an intuitive search
a wealth of information underneath it. Infotips provide faster interface that allows users to visualize the search criteria they
access to an item’s information by providing an instant summary wish to perform on a charted data set. Search criteria can be
view of an item. This view can include information about the quickly created for both single item and linked item searches.
item’s properties. It can also display any supplemental Single item searches can be built based on their type, label,
information, who or what the item is linked to and information date and time, and attributes. Linked item searches take that a
on an item that is sourced from external data sources. Infotips step further by being able to visually specify the search criteria
can also be configured to display only relevant information of for a pair of linked items. This linked search helps to find items
interest so users can identify and highlight the most important or the links between them that match the specified conditions.
information quickly. One example is searching for a “blond male who owns a blue
BMW with license plate number that includes YH57”.
20 IBM i2 Analyst’s Notebook
• French
• German
• Spanish © Copyright IBM Corporation 2017
• Italian IBM Corporation
• Portuguese (Brazilian) IBM Security
• Japanese Route 100
Somers, NY 10589
• Chinese (Simplified)
• Chinese (Traditional) Produced in the United States of America
March 2017
• Korean
• Russian IBM, the IBM logo, ibm.com, i2, and Analyst’s Notebook are trademarks of
International Business Machines Corp., registered in many jurisdictions
• Polish
worldwide. Other product and service names might be trademarks of IBM
• Arabic or other companies. A current list of IBM trademarks is available on the
• Hungarian Web at “Copyright and trademark information” at
www.ibm.com/legal/copytrade.shtml.
• Turkish
• Czech Microsoft, Windows and Windows NT are trademarks of Microsoft
Corporation in the United States, other countries, or both.
• Slovak
• Hebrew This document is current as of the initial date of publication and may
be changed by IBM at any time. Not all offerings are available in every
country in which IBM operates.
For more information
To learn more about IBM i2 Analyst’s Notebook, please The performance data discussed herein is presented as derived under
specific operating conditions. Actual results may vary. It is the user’s
contact your IBM representative, or visit: ibm.com/i2software responsibility to evaluate and verify the operation of any other products
or programs with IBM products and programs. THE INFORMATION IN
To learn more about all of the IBM Smarter Cities solutions, THIS DOCUMENT IS PROVIDED “AS IS” WITHOUT
ANY WARRANTY, EXPRESS OR IMPLIED, INCLUDING
visit: ibm.com/smartercities WITHOUT ANY WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND ANY WARRANTY
OR CONDITION OF NON-INFRINGEMENT. IBM products are
warranted according to the terms and conditions of the agreements under
which they are provided.
The client is responsible for ensuring compliance with laws and regulations
applicable to it. IBM does not provide legal advice or represent or warrant
that its services or products will ensure that the client is in compliance with
any law or regulation.
Please Recycle
ZZW03172-USEN-04