Timeline investigation tools for law enforcement

Watch any good (trashy) police drama and you’ll quickly spot a few cliches. The maverick cop (tough, but with a heart of gold and tragic backstory). The conspicuous killer (the most famous guest star). The irritating chief of police (the only character who can afford a tailored suit).

Among the equally cliched dialogue (“you’re letting it get to you, go home…”) you’ll probably hear demands for a “list of suspects and timeline of events”.

In real and TV policing, timelines are key. They help investigators understand what happened and when, revealing the clear picture they need to solve crimes.

What if it were possible to create these timelines automatically? If investigators had dynamic, interactive, timeline investigation tools? Even better, what if they integrated seamlessly with the link analysis tools they already use? That’s why we built KronoGraph, our timeline visualization toolkit.

Built with KronoGraph: timeline analysis for investigations
Built with KronoGraph: timeline analysis for investigations

In this blog post, we’ll look at one scenario where law enforcement and intelligence agencies use timeline investigation tools to make the world a safer place: call data record (CDR) analysis.

Analyzing call data records (CDR)

Communications and call data holds valuable insight for police and intelligence agencies. They use data from lawful interception, cell phone downloads, tower dumps, and open-source intelligence (OSINT) to build criminal cases and monitor persons of interest. Timeline visualization is the perfect way to analyze it.

Here’s a small part of a dataset representing 23,000 phone calls and messages between 27 students:

Communications between students visualized as a timeline
Communications between students visualized as a timeline

The students, our entities, are listed down the left-hand side of the timeline investigation tool. Their phone calls and text messages are shown as events connecting the entities. The scale runs along the top and bottom of the view.

This simple visual model is flexible enough to accommodate any time-based data. As long as there’s a time or date stamp, KronoGraph will visualize it.

As we zoom out, two smart aggregation techniques simplify the view:

  • Events (phone calls and messages) transition to a heatmap of activity over time
  • Entities (the students) group into four clusters, defined in the original data
In this example, we used our link analysis clustering algorithm to identify four clusters in the data

There’s another powerful way to navigate KronoGraph timelines. Let’s take a look at the lens view.

Managing fraud white paper
FREE: Law enforcement white paper

The ultimate guide to investigating crime, analyzing results and sharing insights using data visualization


Focusing on key timelines without losing focus

No matter how large your dataset, KronoGraph can display every timeline in a single visualization. With this birds-eye view, it’s easy to spot spikes in activity, and which clusters contained less communicative students.

13,000 cellphone calls between 700 students visualized in KronoGraph
413,000 cellphone calls between 700 students visualized in KronoGraph

When we’re ready to take a closer look, we simply enter lens view. This means you can inspect individual timelines without losing context. The scrollbar makes analyzing the details of each call record a smooth, intuitive experience.

Scrolling through the data reveals potential patterns of activity
A screen showing a graph visualization created using KronoGraph
See KronoGraph in action

Take an expert tour with this 20-minute video


Now we know how to navigate our timelines, let’s see what happens when we expand analysis to include network visualization.

Integrated timeline investigation tools

Now, imagine this isn’t a dataset from a social studies research paper, but call data records from an organized crime investigation. The investigators will need to understand the wider network dynamics, to see who’s in charge.

Combining KronoGraph with one of our link analysis toolkits, we get a dual view of our suspects and a timeline.

timeline investigation tools: combining a link analysis with timelines
Combining a link analysis view on the right, with a timeline view on the left.

This hybrid visualization gives two powerful views of a vast and complex CDR dataset. The link analysis chart shows who speaks to whom. The timeline shows when and how they communicate. The interaction is bidirectional, too. Selecting or zooming in one view automatically updates the other:

KronoGraph’s ‘focus’ feature lets us inspect the network of a specific individual or group, in this example by double-clicking on them in either view.

Digging deeper into call data records with centrality measures

We’ve used another social network analysis measure, degree centrality, to highlight the best-connected people in our link chart. Alberta Peters is one of the most prominent Cluster 4 nodes.

Our timeline investigation tool shows she mostly speaks to other people in her cluster, especially Todd Alvarez.

Focusing on Alberta Peters
A timeline investigation into call data records: focusing on Alberta Peters’ connections
She also speaks to Edward Leonard in Cluster 1. All the communication is one-way, though. Why doesn’t Edward return Alberta’s calls?
Focusing on Alberta Peters
A timeline investigation into call data records: focusing on Alberta Peters’ connections

Let’s focus on Edward instead, keeping Alberta pinned (so she always stays in our view).

We can see Edward doesn’t communicate as frequently as other people, but he’s one of only a handful of people with connections to all four clusters.

Focusing on Edward Leonard
Edward has a connection to every other cluster in the network

Is Edward running the network? An interesting lead for an investigator, and one that would be impossible to uncover looking only at the data.

A sneak peek at scale wrapping

We could take our analysis further with a surveillance method called Pattern of Life analysis. This is when law enforcement observes a suspect’s activity to understand their habits and predict their behavior. It’s another great use case for timeline investigation tools.

In this example, we’re looking at a different dataset representing emails sent within a business. Using a feature we call scale wrapping we can change the flow of time in our timeline.

Instead of viewing the email traffic over a linear time period, we can tell KronoGraph to show us the email traffic by hour of day, or day of the week:

Changing the timeline scale to show emails sent by hour of the day, or day of the week

Simply changing our scale reveals new patterns that are otherwise buried. Keep an eye on future blog posts for more detail of scale wrapping, and examples of how it makes pattern of life analysis a breeze.

Find out more about KronoGraph timeline scale wrapping

Build your own timeline investigation tools

Visualizing communications records in KronoGraph helps investigators unpick and understand data on a vast scale. By interacting with the timeline, they can focus on periods of interest and individual connections that help reveal what’s going on.

If you’d like to explore your own data in this way, for law enforcement or other popular data visualization use cases, request a free trial.

A screen showing a hybrid graph and timeline visualization created using ReGraph and KronoGraph
FREE: Start your trial today

Visualize your data! Request full access to our SDKs, demos and live-coding playgrounds.


How can we help you?

Request trial

Ready to start?

Request a free trial

Learn more

Want to learn more?

Read our white papers


Looking for success stories?

Browse our case studies

Registered in England and Wales with Company Number 07625370 | VAT Number 113 1740 61
6-8 Hills Road, Cambridge, CB2 1JP. All material © Cambridge Intelligence 2024.
Read our Privacy Policy.