Professional Documents
Culture Documents
IBM I2 Analyst's Notebook - 8.9.7
IBM I2 Analyst's Notebook - 8.9.7
White Paper
IBM i2 Analyst’s
Notebook
Discover and deliver actionable intelligence to help
identify, predict and prevent criminal, terrorist, and
fraudulent activities
i2 Analyst’s Notebook
unstructured information in a powerful visual analysis environment. It
supports analysts in rapidly building a single, cohesive intelligence picture.
3 Key features of i2 Analyst’s
The results that are delivered from this detailed analysis can then be
shared via intuitive and visual briefing charts or visualizations. These
easy-to-understand visualizations can easily be included in other end
intelligence products. This greatly simplifies the communication of
sometimes complex information and scenarios and ultimately helps
to drive more timely and accurate operational decision making.
IBM Analytics
White Paper
i2 Analyst’s Notebook is a technology road-tested by Who should read this white paper
over 2,000 organizations worldwide. It is designed to This white paper is intended for:
help government agencies and private sector businesses
in their fight against increasingly sophisticated criminal • Potential users of i2 Analyst’s Notebook such as analysts
and terrorist organizations. and investigators who want information about i2 Analyst’s
Notebook and the potential benefits it provides.
• Managers or team leads who want to learn more about
how their teams can use the application most efficiently.
“i2 Analyst’s Notebook offers a wide range of • System administrators who want to gain a high-level
analysis and visualization capabilities that understanding of the product and system prerequisites
that are needed to install and run the application.
can aid in the identification of key actionable
intelligence.” This document relates to i2 Analyst’s Notebook version 8.9.7
2
IBM Analytics
White Paper
Identify connections, patterns, and key intelligence Proven worldwide visual analysis solution
that might otherwise be missed • Over 2,000 organizations worldwide have used this
• Identify the key who, why, what, where and when of any intelligence analysis solution.
analysis question with a wide range of visual analysis tools. • Designed with input garnered from customer experiences
• Combine association, temporal and geospatial aspects of collected in real operational environments.
data with multi-dimensional analysis views. • Comprehensive support infrastructure for global organizations
• Quickly highlight key individuals and relationships and with language versions available in 17 languages.
their connections to key events with core link analysis
capabilities. Key features of i2 Analyst’s Notebook
• Understand critical timeline of events or patterns within
criminal activities with powerful temporal analysis tools. Overview
• Identify potentially important intermediaries between i2 Analyst’s Notebook is a powerful visual analysis
seemingly unconnected entities in a network. environment that offers users a comprehensive range of
capabilities to identify actionable intelligence hidden within
Increase understanding of complex criminal, terrorist, disparate data sets. These capabilities include:
and fraudulent networks
• Gain better insight and understanding of the structure, • Flexible data acquisition tools to quickly ingest a wide
hierarchy and ‘modus-operandi’ of complex networks with variety of data types and formats.
integrated Social Network Analysis tools. • Flexible data modeling and visualization environment that
• Aid the decision-making process and ensure best resource does not constrain the input of complex relational data.
utilization for operational activities in network disruption, • Powerful range of visual analysis capabilities that enables
surveillance or influencing. users to quickly gain increased understanding and reduces
the time to pin-point key intelligence.
Simplify the communication of complex information • Effective dissemination tools that simplify the communication
to support timely and accurate decision making
of complex data and scenarios.
• Clearly communicate complex data and scenarios with
intuitive and easy-to-follow charts and visualizations. Flexible data acquisition
• Drive the effective and efficient sharing of intelligence i2 Analyst’s Notebook provides a range of methods to quickly
for internal teams and across intelligence organizations. ingest the wide variety of information that intelligence
• Effectively share intelligence with a familiar tool that over analysts are faced with everyday. This flexible approach to
2,000 organizations use. data acquisition allows users to input a broad range of data
types. Examples include telephone call records, financial
Rapid deployment delivers near-immediate
transactions, computer IP logs and mobile forensics data,
productivity gains
to name but a few. i2 Analyst’s Notebook’s data acquisition
• Remove the need for professional services deployment
allows users to:
costs with wizard-driven installer.
• Reduce the time to streamline analysis and end intelligence
• Rapidly import structured data via a wizard-style
product generation activities with rapid deployment of
visual importer.
powerful visual analysis capabilities.
• Simplify manual data entry with an intuitive drag and
• Rapid deployment and intuitive, modern user experience
drop mode.
delivers near immediate productivity gains.
• Connect to and query available data sources via numerous
extensibility options.
3
IBM Analytics
White Paper
Visual importing of structured data Drag and drop manual data entry
i2 Analyst’s Notebook users can rapidly import data from i2 Analyst’s Notebook includes manual data entry options that
structured data files via the wizard-style visual importer. are designed to allow rapid chart item creation and editing.
Import specifications that map the data from tabular style files This function provides an intuitive drag and drop interface that
in to an i2 Analyst’s Notebook chart can be quickly created. helps to quickly build chart data. Users are able to choose from
Users are able to visually create how the different data aspects the extensive array of icon types to visually represent real-world
are to be mapped. Inputting this tabular style data into the items or events.
visual environment of i2 Analyst’s Notebook can greatly
increase the potential of discovering key information. It helps
to identify connections and relationships or communication
and commodity flows across a network that would otherwise
remain hidden.
4
IBM Analytics
White Paper
5
IBM Analytics
White Paper
The link analysis environment in i2 Analyst’s Notebook allows Timeline charts are commonly used to analyze information
users to display their data in association charts. The association such as telephone call records (and any other form of
view can be used to show the relationships between entities communications) or financial transactions. They also enable
such as people and organizations and illustrate how they are users to build a picture of a sequence of events for time
interconnected. A wide range of formatting options allows periods of interest. These type of charts provide a powerful
users to quickly and easily represent real-world information. visualization that help to simplify both the analysis and briefing
These extensive options help provide increased insight and of key temporal information.
understanding of a wide variety of ‘networks’. It helps analysts
better understand the relationships within criminal networks, Item property model
the communication patterns between individuals in a network, Users can easily use the following methods to store properties
how money flows across a network and much more. or supplemental information for an item within i2 Analyst’s
Notebook:
Timeline charting
i2 Analyst’s Notebook goes beyond just how entities are • An item’s type is an important property. The type property
interconnected by also allowing information to be portrayed is used to define both entity and link types in a chart. In the
in the form of timeline charts. These temporal views can be case of entities, the type can be used to define the visual
used to illustrate how sequences of events unfold over time. icon style that is displayed in the chart.
They help not only reveal the interactions between entities • Semantic types can be applied to give real-world meaning
but also portray when these interactions occur. for an item type. The real-world meaning helps when
performing a search on a data set. For example, a search for
a person type returns both males and females in the results.
• Other item properties can be stored as attributes against
an item.
6
IBM Analytics
White Paper
• i2 Analyst’s Notebook includes a wide range of entity • Modify the size of entities to identify or emphasize key or
(including associated visual icons), link, and attribute types. important entities within a data set.
However, users can easily create and add their own. • Include other supporting data such as pictures to enhance
• Users (or their organization) can create templates so that briefing charts or reports with images of individuals.
users are only given the option to choose types that are Timeline charts can also be enhanced to include event
most commonly used. Organizations can standardize the frames that depict, for example, CCTV images of an event.
way information is entered across an entire organization. • Display the direction of links to visually represent who
• An image (for example mug shots or CCTV imagery) can called who within a phone call or how money flows
also be stored against an entity. These images can then be between accounts.
used to display on the chart in place of an entity’s visual icon. • Categorize links with the use of color, width, or link
• Supplemental information (that is, extra information on an style. Easily identify differing types of relationship, higher
item from a different source) can be added in the form of volumes of calls between individuals, relative size of financial
cards. These cards provide a method to record text-based transactions between accounts, or the confidence level of a
information against an item while also recording the source. piece of information that links two people together.
• Items can also be graded to record information such as • Group items within a chart to ensure that items can be
source, reliability, and clearance level. The grading structure selected and moved together as a group either manually
is configurable to suit the needs of an organization. or when a user runs one of the analytical layouts.
• Items that are imported from external data sources can also • Change the display status of an item. Items can be hidden
return the property information on those items in the form (the item still exists but is not displayed) or ‘grayed-out’ so
of data records. This rich data can then be used by many of they are de-emphasized compared to other chart items.
the analysis tools within i2 Analyst’s Notebook. Users can then put emphasis on particular items in a chart
but still maintain their context within a wider network.
Item visualization / Formatting
i2 Analyst’s Notebook provides an extensive icon set with a
high-quality, ultra-modern 3D look that offers clear, modern,
and detailed real-world representations in charts. The extensive
range of icons that are provided includes individual sets that are
targeted at specific sectors. These icon sets include Defense,
Cyber, Telephone, and Financial / Fraud analysis to name a few.
7
IBM Analytics
White Paper
8
IBM Analytics
White Paper
Histogram view filtering — Histogram filters provide a Temporal analysis and visualization
powerful mechanism for quickly delivering visual feedback Answering the ‘when’ question is a critical need for most tasks
on a range of data types that are contained within any chart. that are posed to intelligence analysts and their organizations.
This interactive view is highly suitable for range-based data i2 Analyst’s Notebook provides a set of temporal analysis tools
types such as date/time or transactional amounts. It allows that help in understanding the temporal aspects of any data
users to identify areas of interest in chart data set such as set. These powerful tools help analysts to:
peaks, troughs, or patterns in activities. Users can then drill
down to quickly highlight any relevant information. • Drill down in to the temporal aspects of an entire charted
data set with instant, interactive visual temporal views.
The interactive histogram view provides the following capabilities: • Identify areas of interest within chart data, such as
temporal peaks, troughs, or patterns in activities that
• Select single or multiple bars in the histogram view to require further investigation.
highlight the corresponding items within the main chart view. • Understand potential temporal trends such as activities
• Drill down to perform more detailed analysis of a data set. that occur more at a particular time of day and day of week.
Users can display a more granular view of the entire data • Create a more detailed timeline view of activities for
set or display the information for a selected range only. items of interest down to individual event granularity.
• Run an animation of chart data to show how activities
occur over time or how a data set builds over time. Activity View — To fully understand a timeline of events
• Copy the histogram view as a bitmap to allow easier there is the need for analysts to understand a timeline down
integration into reports or presentations. to individual event granularity. Many of these events also
occur over time. It is vitally important to be able to record
List view filtering — List view filters provide effective and and visualize the duration over which any particular event
fast visual feedback for non-range-based data with a chart occurred. The Activity view in i2 Analyst’s Notebook allows
data set. This visual statistical summary can be used for any users to do just that. The ‘Gantt-style’ temporal visualization
aspect of a charted data set. It can offer quick insight into the allows users to plot, down to individual event granularity, all
information that is contained within. Multiple list view filters time-based activities that occur within selected chart data.
can also be used to quickly identify commonality within items Both ‘point-in-time’ events and activities that occur over time
in a chart that is based on complex filter criteria. can be plotted with the Activity view. It provides users with a
full view of an item’s activity timeline.
9
IBM Analytics
White Paper
This detailed temporal view greatly reduces the time that is Users can perform a more detailed analysis of a data set with
required to re-create and then understand any critical timeline interactive histogram view. Data can be viewed at a more
of events. It also helps analysts to identify potential anomalies granular level (for example, show by days instead of months).
within a timeline. It can highlight overlaps in an individual’s It can also display the data for a selected range only (for example,
activities (such as being in two places at the same time). It also show only the items in June).
more clearly highlights time periods with no information,
helping to pinpoint areas for further data-gathering by The histogram view also works interactively with the main
operational teams. chart view. Data that falls outside the selected time period
within the histogram can be hidden or ‘grayed-out’ within the
The activity view can also be used side-by-side with a network chart. Users can then display both association information
chart, allowing analysts to compare both association and within the main chart and temporal information within the
temporal aspects simultaneously. histogram simultaneously. This combination is designed
to help users to gain better insight into how, over time,
Histogram view — The histogram functionality in i2 Analyst’s communications occur between individuals or how finances
Notebook provides a powerful tool to display temporal data. might flow across a network.
The interactive view allows analysts to select time periods of
interest and filter out non-relevant information that falls Heat matrix view — The heat matrix takes the temporal
outside these times. This powerful capability helps users to analysis of a charted data set a step further. It offers a more
quickly identify potential time periods of interest, such as peaks, detailed breakdown of the temporal content of data, allowing
troughs, or patterns in activities, in a chart data set. Users can users to map/visualize activities against two temporal ranges.
then drill down in these areas of interest to gain better insight This capability helps to provide a much quicker answer to
in to the potential causes. temporal questions, do activities happen at a certain time of
day AND a particular day of the week?
10
IBM Analytics
White Paper
This understanding can help users to quickly identify patterns The relationships between prominent people of interest who
in activity or aspects of a target’s likely pattern of life. It also wield the greatest influence over the rest of the network can be
helps identify how and when a target individual works or understood better. SNA also helps identify how directly and
whether there are any regular patterns in terms of their quickly information flows between people in different parts of
common activities. the network.
The heat matrix view, in the same way as the histogram view, Using SNA measures can help analysts to understand individuals’
works interactively with the main chart view. roles within a network. Coupled with the temporal analysis
capabilities within i2 Analyst’s Notebook, SNA can help identify
Social network analysis so-called Emerging Leaders and Rising Stars. These individuals
i2 Analyst’s Notebook provides analysts with the means to are people who increase in importance or influence within a
increase understanding of the structure, hierarchy and modus network over time.
operandi of criminal and terrorist networks.
Better understanding of a network, its structure, hierarchy, and
Social network analysis (SNA) has emerged as an effective individuals’ roles within a network is vitally important. This
intelligence analysis technique. It enables the analysis of how understanding helps drive better operational decision making
and why social groups operate, interact and behave in particular whether for network disruption, surveillance, or information
ways. This quantitative technique enables users to map and access and dissemination purposes.
measure complex networks of entities such as people and
organizations, by measuring the interactions between them.
SNA techniques can also help give insights into the performance
of a network as a whole and its ability to achieve its key
goals. It helps to identify characteristics of a network that
normally are not immediately obvious, such as the existence
of smaller subnetworks that operate within a larger group.
11
IBM Analytics
White Paper
The SNA centrality measures that are included in i2 Analyst’s Find connecting networks
Notebook are: i2 Analyst’s Notebook offers users the means to help identify
potential important intermediaries between entities in a network.
Degree Centrality — Identifies entities who are the most
active in a network that is based on the number of direct links The Find Connecting Networks feature helps users to identify
to other entities potential intermediaries between seemingly unconnected
entities and highlight possible networks that connect multiple
Closeness Centrality — Identifies entities who have the best entities of interest.
access to other parts of a network and visibility of activities
within the rest of a network One example of this is searching for a network that joins several
bank accounts that are involved in fraud. Find Connecting
Betweenness Centrality — Identifies entities who act as Network results could help to identify an intermediate account
gatekeepers or bridges of information and control information or accounts that distribute money to those accounts and
flow between different parts of a network possibly play a central role in the fraudulent activity.
Eigenvector Centrality — Identifies how well-connected an Users can control this analysis to:
entity is and how much direct influence it has over the most
active entities in the network • Exclude specific entity or link types to refine the search
such as concentrating just on actual communication or
i2 Analyst’s Notebook also includes an SNA clustering transactional information.
technique in the form of K-Cores. This clustering measure • Exclude specific entities to remove those known not be
can help identify tightly interlinked groups within a network; involved in investigations.
this information points to potentially smaller subnetworks • Test hypothesis by excluding items to help identify potential
that operate within a wider group. effects of removing that entity from a network, for example
the effects of freezing a bank account on the movement of
SNA can also be enhanced by the use of weightings. These funds between other accounts of interest.
scores help to indicate the strength of differing relationships • Format the results on the chart to help to clearly
(links), each of which can affect a target network. Weighting communicate analysis findings.
relationships helps to deliver a more real-world indication of
the dynamics and structure of a target network.
12
IBM Analytics
White Paper
Geospatial analysis
Combining geospatial data and understanding with both
association and temporal understanding is a key requirement for
analysts and their organizations. The combined understanding
of all these aspects helps to facilitate turning information into a
full intelligence picture. The Google Earth Exporter within i2
Analyst’s Notebook enables users to export selected chart data
to an installed Google Earth client. More detailed geospatial
analysis is also available with the addition of the optional
IBM i2 Analyst’s Notebook Connector for Esri.
13
IBM Analytics
White Paper
Find Matching Entities — With data potentially coming These definitions can be used to align data from different
from different data sources, situations commonly arise where sources. Better data alignment improves the accuracy of any
data imported into a chart has differing unique identities but potential matching and reduces the time that is taken to
refers to the same real-world object. This situation could identify possible duplicates. These ranked results help in the
involve people who are imported from different data systems, final human-led decision as to whether the items are the same
where name formats are different or name synonyms used and can be merged into a single item.
(Danny instead of Daniel). Items also could have been
imported with different unique identities but have a number Search and discovery
of equivalent properties behind them. The use of an alias With the ability to ingest a wide variety of information from a
name is one example. wide variety of sources comes the need to be able to efficiently
search that data. Effective search techniques are vital to allow
users to quickly identify information of interest, key connections,
or patterns that are hidden within any charted data set.
14
IBM Analytics
White Paper
15
IBM Analytics
White Paper
16
IBM Analytics
White Paper
Sharing chart information — Often information that is IBM i2 Analyst’s Notebook Premium
identified within a chart is required for other end intelligence IBM i2 Analyst’s Notebook Premium builds on the powerful
reports in differing formats. i2 Analyst’s Notebook provides visual analysis capabilities of i2 Analyst’s Notebook. It provides
a number of methods that allow users to: a rich data-centric analysis environment complete with an
optimized local analysis repository. It further helps to reduce
• Copy or save a whole chart or parts of a chart to various the costs that are associated in uncovering key connections,
image formats (.bmp, .jpg, .png). These visuals can then networks, patterns, and trends to help predict and prevent
be used in other intelligence documents. criminal, terrorist, and fraudulent activities
• Copy or save a view of the visual results of i2 Analyst’s
Notebook analysis tools. These tools include the It includes all the key elements that are required for single
Histogram, Heat Matrix, and Activity views. users to collate, manage, explore, and analyze all of their
• Export all snapshots of a chart that are taken with the local information.
Snapshot tool to a Microsoft PowerPoint presentation.
• Export a whole chart or parts of a chart to an Adobe • Local analysis repository that is optimized for data
PDF document. management, information discovery, and analysis.
• Data management interface to enable rapid data entry
Chart redaction — i2 Analyst’s Notebook provides the means and management, as well as powerful search and discovery
to grade all data within a chart. The grading aids in recording capabilities.
information such as confirmation status, reliability of source or • Near-seamless integration with the powerful capabilities
security clearance level. Users are also provided with the ability of the rich visual analysis environment empowers users to
to save a redacted version of a chart. Redacted versions can quickly build multi-dimensional views on the identified data
be created to include information that is based on either the of interest.
grading level of items within a chart or on a specific property.
This capability allows users to easily share chart information IBM i2 Analyst’s Notebook SDK
with others who have a lower security level. Users can quickly i2 Analyst’s Notebook SDK (software development kit) enables
create separate charts with all ‘sensitive’ information removed. organizations to extend i2 Analyst’s Notebook to meet their
individual requirements. It provides technical specialists with
IBM i2 Chart Reader — i2 Analyst’s Notebook charts can also the software, documentation, and sample materials that are
be shared electronically to anybody who does not have access to required to extend and enhance (through development) the
i2 Analyst’s Notebook. IBM i2 Chart Reader is available at no functionality available within i2 Analyst’s Notebook.
charge and provides read-only access to charts that can then be
navigated, searched, or printed. Rich information behind chart i2 Analyst’s Notebook SDK empowers developers, by using the
entities and links can also be searched and read. i2 Analyst’s Notebook API, to:
17
IBM Analytics
White Paper
18
IBM Analytics
White Paper
• French
• German
• Spanish
• Italian
• Portuguese (Brazilian)
• Japanese
• Chinese (Simplified)
• Chinese (Traditional)
• Korean
• Russian
• Polish
• Arabic
• Hungarian
• Turkish
• Czech
• Slovak
• Hebrew
19
© Copyright IBM Corporation 2015
IBM Analytics
Route 100
Somers, NY 10589
IBM, the IBM logo, ibm.com, i2, and Analyst’s Notebook are trademarks
of International Business Machines Corp., registered in many
jurisdictions worldwide. Other product and service names might be
trademarks of IBM or other companies. A current list of IBM trademarks
is available on the Web at “Copyright and trademark information” at
www.ibm.com/legal/copytrade.shtml.
Please Recycle
ZZW03172-USEN-03