Picviz: finding a needle in a haystack

  • Authors:
  • Sebastien Tricaud

  • Affiliations:
  • INL

  • Venue:
  • WASL'08 Proceedings of the First USENIX conference on Analysis of system logs
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

When considering log files for security, usual applications available today either look for patterns using signature databases or use a behavioral approach. In both cases, information can be missed. The problem becomes bigger with systems receiving a massive amount of logs. Parallel coordinates is an answer to display an infinity of events in multiple dimensions. As security data are multivariate, parallel coordinates provides a neat way to display and ease abnormal behaviors detection. Picviz implements the use of parallel coordinates on acquired data, such as logs, to create a parallel coordinates image. Using this image, the analyst can use Picviz to improve the output image, filter information and visually detect things. Finally, based on what the image helped to detect, the analyst can then write automatic tools and avoid the human interaction with the image.