DocumentCode :
119473
Title :
Weaving a carpet from log entries: A network security visualization built with co-creation
Author :
Landstorfer, Johannes ; Herrmann, Ivo ; Stange, Jan-Erik ; Dork, Marian ; Wettach, Reto
Author_Institution :
Dept. of Design, Univ. of Appl. Sci. Potsdam, Potsdam, Germany
fYear :
2014
fDate :
25-31 Oct. 2014
Firstpage :
73
Lastpage :
82
Abstract :
We created a pixel map for multivariate data based on an analysis of the needs of network security engineers. Parameters of a log record are shown as pixels and these pixels are stacked to represent a record. This allows a broad view of a data set on one screen while staying very close to the raw data and to expose common and rare patterns of user behavior through the visualization itself (the "Carpet"). Visualizations that immediately point to areas of suspicious activity without requiring extensive filtering, help network engineers investigating unknown computer security incidents. Most of them, however, have limited knowledge of advanced visualization techniques, while many designers and data scientists are unfamiliar with computer security topics. To bridge this gap, we developed visualizations together with engineers, following a co-creative process. We will show how we explored the scope of the engineers\´ tasks and how we jointly developed ideas and designs. Our expert evaluation indicates that this visualization helps to scan large parts of log files quickly and to define areas of interest for closer inspection.
Keywords :
computer network security; data visualisation; system monitoring; Carpet; cocreative process; computer security incidents; inspection; log entries; log files; log record parameters; multivariate data pixel map; network security engineering; network security visualization; suspicious activity; user behavior pattern; visualization technique; Visual analytics; Pixel-oriented techniques; multidimensional data; network security and intrusion; task and requirements analysis;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Visual Analytics Science and Technology (VAST), 2014 IEEE Conference on
Conference_Location :
Paris
Type :
conf
DOI :
10.1109/VAST.2014.7042483
Filename :
7042483
Link To Document :
بازگشت