Justin Lancaster Product Design
All work 004

Helix: Cloud Security Platform

A visualization system that parses complex detection data and renders it as a clear story — cutting the time it took junior analysts to assess an alert.

Company
FireEye
Context
Security Operations Platform
My role
Lead UX Designer
Year
2020
Outcome

Significantly reduced analyst triage time and alert volume

Overview

Helix was FireEye's premier cloud-hosted security operations platform, letting organizations take control of an incident from alert to fix. It integrated multiple standalone and on-premise products into a single experience and augmented them with advanced threat protection.

Platform capabilities

  • Next-generation SIEM
  • Security orchestration
  • Threat intelligence
  • Alert workflow management
  • Investigation and case management
  • Unified, customizable dashboards
  • Advanced reporting

My role

  • Led UX design for FireEye's flagship next-generation cloud security platform.
  • Conducted UX research to develop data and insights, test assumptions, and guide development of new features toward business goals and user needs.
  • Worked closely with Product and Engineering to develop a powerful alert workflow module.
  • Helped guide strategy and design for integrating FireEye's services into the UI, working with Product and Engineering leads from both teams.
  • Created an alert visualization system to render complex detection data visually, reducing the time it took junior analysts to assess alerts.

Case study: alert visualization

The problem

The conventional approach to alert management is confusing and time-consuming. Alerts are largely managed in a vacuum, as a single event in time. Users are presented with alert data that is highly technical and data-dense, making it hard to understand what actually happened. Newer analysts lack the skills to interpret the alert. Reaching a conclusion often takes multiple steps across different tools — and it is left to the analyst to determine what action to take.

Previous design

The solution

An interactive visualization library able to parse complex alert data and render it as a clear picture of what happened. The visualizations told the story of:

  • What triggered the alert
  • Who was affected
  • Events that occurred or were attempted
  • Mitigations taken automatically
  • Source and destination
  • Whether something is malicious or benign
  • Intel enrichment — known good, bad, or unknown
  • Any related or correlated alerts
New design

The process

In discovery we decided to focus on making the software easier for junior analysts to use. I set up a working group including Product and Data Science leads that met regularly for collaboration sessions and design review, and facilitated a strategy workshop using the Lean UX Canvas to define business goals, metrics, and hypotheses.

From there I led the effort from discovery to deployment:

  • Crafted a research plan and interview questions
  • Conducted user interviews
  • Synthesized findings to understand user needs
  • Created designs and prototypes for testing
  • Ran usability tests to confirm the designs solved the right problems
  • Ran A/B impression tests to further refine
  • Iterated continuously, validating with users and key stakeholders along the way
  • Broke the designs down into a component library and a mini design system able to render every different type of alert
Working sessions — synthesising user research with Product and Data Science
Component breakdown

Impact and results

The experience increased analyst efficiency by creating a system that parses complex alert data and renders it in consistent, easy-to-understand visualizations. It provided context and encouraged users to inspect elements to see detail and take the appropriate action to remediate a threat.

  • Analyst triage time and alert volume both dropped significantly. Reading an alert stopped being an investigation in itself.
  • Junior analysts could work the queue. The visualisation answered what triggered the alert, who was affected, and what had already been mitigated — removing the escalation to a senior analyst that interpreting raw detection data used to require.
  • One system rendered every alert type. The component library underneath meant new detection types inherited the visual language instead of needing bespoke design.
  • Validated before launch. Usability testing and A/B impression testing confirmed the designs solved the problem rather than simply looking different.
The complete threat view — correlated email, endpoint, and network activity, with a timeline of related events and a confidence-scored risk assessment
What triggered the alert — endpoint, process, and the disguised file
Events that occurred, with intel enrichment from detonation in the FireEye virtual environment
Mitigations taken automatically — a blocked outbound connection
Alert detail
Correlated alerts & intel enrichment
Visualization variants