Visualization of security event logs across multiple networks and its application to a CSOC

被引:0
|
作者
Boyeon Song
Jangwon Choi
Sang-Soo Choi
Jungsuk Song
机构
[1] Korea Institute of Science and Technology Information (KISTI),
来源
Cluster Computing | 2019年 / 22卷
关键词
Intrusion detection system; Information visualization; Cyber security; Network security;
D O I
暂无
中图分类号
学科分类号
摘要
We introduce VisIDAC presented in Song at al (In: Nguyen, P.Q., Zhou, J. (eds.) Information Security—20th International Conference, ISC 2017, Security and Cryptology, vol. 10599. Springer International Publishing, 2017), which is a 3-D real-time visualization of security event log collection detected by intrusion detection systems installed in multiple networks. VisIDAC consists of three parallel plane-squares which represent global source networks, target networks, and global destination networks. Security events are displayed in different shapes, colors and spaces, according to their main features. It helps security operators to immediately understand the key properties of security events. We also apply VisIDAC to a public cyber security operations center, Science and Technology Cyber Security Center (S&T-CSC), and demonstrate its usefulness. VisIDAC allows users to grasp more intuitively the overall flow of security events and their trend, makes it easy to recognize large-scale security events such as network scanning, port scanning, and distributed denial of service attacks, and is also effective to distinguish security event types: which target network they are related to; whether they are inbound or outbound traffic; whether they are momentary or continuous; and what protocol and port number are mainly used.
引用
收藏
页码:1861 / 1872
页数:11
相关论文
共 50 条
  • [1] Visualization of security event logs across multiple networks and its application to a CSOC
    Song, Boyeon
    Choi, Jangwon
    Choi, Sang-Soo
    Song, Jungsuk
    [J]. CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2019, 22 (Suppl 1): : 1861 - 1872
  • [2] Digital water networks visualization and its integration application
    State Key Laboratory of Eco-hydrologic Engineering in Northwest in the Arid Area, Xi’an University of Technology, Xi’an
    710048, China
    [J]. W. Resour. Prot, 2020, 6 (39-45):
  • [3] Behavior Rhythm: A New Model for Behavior Visualization and Its Application in System Security Management
    Liu, Zhaoli
    Guan, Xiaohong
    Li, Shancang
    Qin, Tao
    He, Chao
    [J]. IEEE ACCESS, 2018, 6 : 73940 - 73951
  • [4] Intelligent Computing on the Basis of Cognitive and Event Modeling, and Its Application in Energy Security Research
    Massel, L. V.
    Arshinsky, V. L.
    Massel, A. G.
    [J]. INTERNATIONAL JOURNAL OF ENERGY OPTIMIZATION AND ENGINEERING, 2014, 3 (01) : 83 - 91
  • [5] A new concentric-circle visualization of multi-dimensional data and its application in network security
    Lu, Liang Fu
    Zhang, Jia Wan
    Huang, Mao Lin
    Fu, Lei
    [J]. JOURNAL OF VISUAL LANGUAGES AND COMPUTING, 2010, 21 (04): : 194 - 208
  • [6] Multi-Timer Based Event Synchronization Control for Sensor Networks and Its Application
    Qin, Jiahu
    Li, Fangyuan
    Mou, Shaoshuai
    Kang, Yu
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2016, 63 (12) : 7765 - 7775
  • [7] Research of multivariable GPC based on multiple Hopfield networks and its application
    Guo, P
    Chang, TH
    [J]. Proceedings of 2005 International Conference on Machine Learning and Cybernetics, Vols 1-9, 2005, : 4184 - 4187
  • [8] Cellular neural networks with multiple-valued output and its application
    Kanagawa, A
    Kawabata, H
    Takahashi, H
    [J]. IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 1996, E79A (10) : 1658 - 1663
  • [9] Novel Model of Security Region of Metering Networks and Its Application in Meters' Status Estimation
    Zhou Feng
    Cheng Yingying
    Zhou Huayong
    Xiao Ji
    [J]. PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND MANAGEMENT INNOVATION, 2015, 28 : 42 - 46
  • [10] A Multimedia Data Visualization Based on Ad Hoc Communication Networks and Its Application to Disaster Management
    Kawamura, Youhei
    Wagner, Markus
    Jang, Hyongdoo
    Nobuhara, Hajime
    Shibuya, Takeshi
    Kitahara, Itaru
    Dewan, Ashraf M.
    Veenendaal, Bert
    [J]. ISPRS INTERNATIONAL JOURNAL OF GEO-INFORMATION, 2015, 4 (04): : 2004 - 2018