• DocumentCode
    3636131
  • Title

    Explorative Visualization of Log Data to Support Forensic Analysis and Signature Development

  • Author

    Sebastian Schmerl;Michael Vogel;René Rietz;Hartmut König

  • Author_Institution
    Comput. Networks &
  • fYear
    2010
  • Firstpage
    109
  • Lastpage
    118
  • Abstract
    Today’s growing number of security threats to computers and networks also increase the importance of log inspections to support the detection of possible breaches. The investigation and assessment of security incidents becomes more and more a daily business. Further, the manual log analysis is essentially in the context of developing signatures for intrusion detection systems (IDS), which allow for an automated defense against security attacks or incidents. But the analysis of log data in the context of fo-rensic investigations and IDS signature development is a tedious and time-consuming task, due to the large amount of textual data. Moreover, this task requires a skilled knowledge to differentiate between the important and the non-relevant information. In this paper, we propose an approach for log resp. audit data representation, which aims at simplifying the analysis process for the security officer. For this purpose audit data and existing relations between audit events are represented graphically in a three-dimensional space. We describe a general approach for analyzing and exploring audit or log data in the context of this presentation paradigm. Further, we introduce our tool, which implements this approach and demonstrate the strengths and benefits of this presentation and exploration form.
  • Keywords
    "Data visualization","Digital forensics","Information security","Data security","Communication networks","Communication system security","Character generation","Proposals","Information analysis","Event detection"
  • Publisher
    ieee
  • Conference_Titel
    Systematic Approaches to Digital Forensic Engineering (SADFE), 2010 Fifth IEEE International Workshop on
  • Print_ISBN
    978-0-7695-4052-8
  • Type

    conf

  • DOI
    10.1109/SADFE.2010.10
  • Filename
    5491960