DocumentCode :
3636131
Title :
Explorative Visualization of Log Data to Support Forensic Analysis and Signature Development
Author :
Sebastian Schmerl;Michael Vogel;René Rietz;Hartmut König
Author_Institution :
Comput. Networks &
fYear :
2010
Firstpage :
109
Lastpage :
118
Abstract :
Today’s growing number of security threats to computers and networks also increase the importance of log inspections to support the detection of possible breaches. The investigation and assessment of security incidents becomes more and more a daily business. Further, the manual log analysis is essentially in the context of developing signatures for intrusion detection systems (IDS), which allow for an automated defense against security attacks or incidents. But the analysis of log data in the context of fo-rensic investigations and IDS signature development is a tedious and time-consuming task, due to the large amount of textual data. Moreover, this task requires a skilled knowledge to differentiate between the important and the non-relevant information. In this paper, we propose an approach for log resp. audit data representation, which aims at simplifying the analysis process for the security officer. For this purpose audit data and existing relations between audit events are represented graphically in a three-dimensional space. We describe a general approach for analyzing and exploring audit or log data in the context of this presentation paradigm. Further, we introduce our tool, which implements this approach and demonstrate the strengths and benefits of this presentation and exploration form.
Keywords :
"Data visualization","Digital forensics","Information security","Data security","Communication networks","Communication system security","Character generation","Proposals","Information analysis","Event detection"
Publisher :
ieee
Conference_Titel :
Systematic Approaches to Digital Forensic Engineering (SADFE), 2010 Fifth IEEE International Workshop on
Print_ISBN :
978-0-7695-4052-8
Type :
conf
DOI :
10.1109/SADFE.2010.10
Filename :
5491960
Link To Document :
بازگشت