LongLine: Visual Analytics System for Large-scale Audit Logs

被引:6
作者
Yoo, Seunghoon [1 ]
Jo, Jaemin [1 ]
Kim, Bohyoung [2 ]
Seo, Jinwook [1 ]
机构
[1] Seoul Natl Univ, Seoul, South Korea
[2] Hankuk Univ Foreign Studies, Seoul, South Korea
来源
VISUAL INFORMATICS | 2018年 / 2卷 / 01期
关键词
Visual Analytics; Log Visualization; Multidimensional Data;
D O I
10.1016/j.visint2018.04.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Audit logs are different from other software logs in that they record the most primitive events (i.e., system calls) in modem operating systems. Audit logs contain a detailed trace of an operating system, and thus have received great attention from security experts and system administrators. However, the complexity and size of audit logs, which increase in real time, have hindered analysts from understanding and analyzing them. In this paper, we present a novel visual analytics system, LongLine, which enables interactive visual analyses of large-scale audit logs. LongLine lowers the interpretation barrier of audit logs by employing human-understandable representations (e.g., file paths and commands) instead of abstract indicators of operating systems (e.g., file descriptors) as well as revealing the temporal patterns of the logs in a multi-scale fashion with meaningful granularity of time in mind (e.g., hourly, daily, and weekly). LongLine also streamlines comparative analysis between interesting subsets of logs, which is essential in detecting anomalous behaviors of systems. In addition, LongLine allows analysts to monitor the system state in a streaming fashion, keeping the latency between log creation and visualization less than one minute. Finally, we evaluate our system through a case study and a scenario analysis with security experts. (C) 2018 Published by Elsevier B.V. on behalf of Zhejiang University and Zhejiang University Press.
引用
收藏
页码:82 / 97
页数:16
相关论文
共 50 条
  • [41] OccVis: a visual analytics system for occultation data
    Shiyu Cheng
    Guihua Shan
    Jun Liu
    Yang Gao
    Ping Wei
    Weihua Bai
    Danyang Zhao
    Journal of Visualization, 2019, 22 : 609 - 624
  • [42] A Visual Analytics System for Breast Tumor Evaluation
    Petushi, Sokol
    Marker, Jeffrey
    Zhang, Jasper
    Zhu, Weizhong
    Breen, David
    Chen, Chaomei
    Lin, Xia
    Garcia, Fernando U.
    ANALYTICAL AND QUANTITATIVE CYTOLOGY AND HISTOLOGY, 2008, 30 (05): : 279 - 290
  • [43] TVseer: A visual analytics system for television ratings
    Kui, Xiaoyan
    Lv, Huihao
    Tang, Zhengliang
    Zhou, Haowen
    Yang, Wang
    Li, Jinqiu
    Guo, Jialin
    Xia, Jiazhi
    VISUAL INFORMATICS, 2020, 4 (03) : 1 - 11
  • [44] VAIT: A Visual Analytics System for Metropolitan Transportation
    Liu, Siyuan
    Pu, Jiansu
    Luo, Qiong
    Qu, Huamin
    Ni, Lionel M.
    Krishnan, Ramayya
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2013, 14 (04) : 1586 - 1596
  • [45] The Top 10 Challenges in Extreme-Scale Visual Analytics
    Wong, Pak Chung
    Shen, Han-Wei
    Johnson, Christopher R.
    Chen, Chaomei
    Ross, Robert B.
    IEEE COMPUTER GRAPHICS AND APPLICATIONS, 2012, 32 (04) : 63 - 67
  • [46] CKM: A Shared Visual Analytical Tool for Large-Scale Analysis of Audio-Video Interviews
    Xiao, Lu
    Luo, Yan
    High, Steven
    2013 IEEE INTERNATIONAL CONFERENCE ON BIG DATA, 2013,
  • [47] VALID: A Web Framework for Visual Analytics of Large Streaming Data
    Li, Chenhui
    Baciu, George
    2014 IEEE 13TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM), 2014, : 686 - 692
  • [48] Have green - A visual analytics framework for large semantic graphs
    Wong, Pak Chung
    Chin, George, Jr.
    Foote, Harlan
    Mackey, Patrick
    Thomas, Jim
    VAST 2006: IEEE SYMPOSIUM ON VISUAL ANALYTICS SCIENCE AND TECHNOLOGY, PROCEEDINGS, 2006, : 67 - +
  • [49] Realizing embodied interaction for visual analytics through large displays
    Ball, Robert
    North, Chris
    COMPUTERS & GRAPHICS-UK, 2007, 31 (03): : 380 - 400
  • [50] LEVA: Using Large Language Models to Enhance Visual Analytics
    Zhao, Yuheng
    Zhang, Yixing
    Zhang, Yu
    Zhao, Xinyi
    Wang, Junjie
    Shao, Zekai
    Turkay, Cagatay
    Chen, Siming
    IEEE TRANSACTIONS ON VISUALIZATION AND COMPUTER GRAPHICS, 2025, 31 (03) : 1830 - 1847