LongLine: Visual Analytics System for Large-scale Audit Logs

被引:6
|
作者
Yoo, Seunghoon [1 ]
Jo, Jaemin [1 ]
Kim, Bohyoung [2 ]
Seo, Jinwook [1 ]
机构
[1] Seoul Natl Univ, Seoul, South Korea
[2] Hankuk Univ Foreign Studies, Seoul, South Korea
来源
VISUAL INFORMATICS | 2018年 / 2卷 / 01期
关键词
Visual Analytics; Log Visualization; Multidimensional Data;
D O I
10.1016/j.visint2018.04.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Audit logs are different from other software logs in that they record the most primitive events (i.e., system calls) in modem operating systems. Audit logs contain a detailed trace of an operating system, and thus have received great attention from security experts and system administrators. However, the complexity and size of audit logs, which increase in real time, have hindered analysts from understanding and analyzing them. In this paper, we present a novel visual analytics system, LongLine, which enables interactive visual analyses of large-scale audit logs. LongLine lowers the interpretation barrier of audit logs by employing human-understandable representations (e.g., file paths and commands) instead of abstract indicators of operating systems (e.g., file descriptors) as well as revealing the temporal patterns of the logs in a multi-scale fashion with meaningful granularity of time in mind (e.g., hourly, daily, and weekly). LongLine also streamlines comparative analysis between interesting subsets of logs, which is essential in detecting anomalous behaviors of systems. In addition, LongLine allows analysts to monitor the system state in a streaming fashion, keeping the latency between log creation and visualization less than one minute. Finally, we evaluate our system through a case study and a scenario analysis with security experts. (C) 2018 Published by Elsevier B.V. on behalf of Zhejiang University and Zhejiang University Press.
引用
收藏
页码:82 / 97
页数:16
相关论文
共 50 条
  • [31] Towards Progressively Detecting Faults in a Large Power System: A Visual Analytics Approach
    Xie, Rengan
    Wang, Fei
    Li, Wenchen
    Huang, Yanhao
    Peng, Wenjie
    Zhang, Shujun
    Zheng, Wenting
    IEEE TRANSACTIONS ON INDUSTRY APPLICATIONS, 2023, 59 (03) : 2904 - 2912
  • [32] A VISUAL ANALYTICS FRAMEWORK FOR LARGE TRANSPORTATION DATASETS
    Zhong, Chen
    Arisona, Stefan Muller
    Schmitt, Gerhard
    PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON COMPUTER-AIDED ARCHITECTURAL DESIGN RESEARCH IN ASIA (CAADRIA 2014): RETHINKING COMPREHENSIVE DESIGN: SPECULATIVE COUNTERCULTURE, 2014, : 223 - 232
  • [33] DendroMap: Visual Exploration of Large-Scale Image Datasets for Machine Learning with Treemaps
    Bertucci D.
    Hamid M.M.
    Anand Y.
    Ruangrotsakun A.
    Tabatabai D.
    Perez M.
    Kahng M.
    IEEE Transactions on Visualization and Computer Graphics, 2023, 29 (01) : 320 - 330
  • [34] Reconfigurable Visual Computing Architecture for Extreme-Scale Visual Analytics
    Su, Simon
    Barton, J. Michael
    An, Michael
    Perry, Vincent
    Panneton, Brian
    Bravo, Luis
    Kannan, Rajgopal
    Dasari, Venkateswara
    DISRUPTIVE TECHNOLOGIES IN INFORMATION SCIENCES, 2018, 10652
  • [35] GameDepot: A Visual Analytics System for Mobile Game Performance Testing
    Jang, Donghoon
    Jo, Jaemin
    IEEE ACCESS, 2023, 11 : 83251 - 83263
  • [36] On the Integration of Large-Scale Time Series Distance Matrices Into Deep Visual Analytic Tools
    Santamaria-Valenzuela, Inmaculada
    Rodriguez-Fernandez, Victor
    Camacho, David
    COGNITIVE COMPUTATION, 2025, 17 (01)
  • [37] Ensemble Visual Analysis Architecture with High Mobility for Large-Scale Critical Infrastructure Simulations
    Eaglin, Todd
    Wang, Xiaoyu
    Ribarsky, William
    Tolone, William
    VISUALIZATION AND DATA ANALYSIS 2015, 2015, 9397
  • [38] OccVis: a visual analytics system for occultation data
    Cheng, Shiyu
    Shan, Guihua
    Liu, Jun
    Gao, Yang
    Wei, Ping
    Bai, Weihua
    Zhao, Danyang
    JOURNAL OF VISUALIZATION, 2019, 22 (03) : 609 - 624
  • [39] Reflections on the evolution of the Jigsaw visual analytics system
    Goerg, Carsten
    Liu, Zhicheng
    Stasko, John
    INFORMATION VISUALIZATION, 2014, 13 (04) : 336 - 345
  • [40] Sunfall: A collaborative visual analytics system for astrophysics
    Aragon, Cecilia R.
    Bailey, Stephen J.
    Poon, Sarah
    Runge, Karl J.
    Thomas, Rollin C.
    VAST: IEEE SYMPOSIUM ON VISUAL ANALYTICS SCIENCE AND TECHNOLOGY 2007, PROCEEDINGS, 2007, : 219 - +