Change search
ReferencesLink to record
Permanent link

Direct link
LogWheels: A Security Log Visualizer
Norwegian University of Science and Technology, Faculty of Information Technology, Mathematics and Electrical Engineering, Department of Computer and Information Science.
2011 (English)MasteroppgaveStudent thesis
Abstract [en]

Logging security incidents is a required security measure in every moderately complex computer system. But while most systems produce large quantities of textual logs, these logs are often neglected or infrequently monitored by untrained personnel. One of the reasons for this neglect is the poor usability offered by distributed repositories of plain text log data, using different log formats and contradictory terminology. The use of security visualization has established itself as a promising research area, aiming to improve the usability of security logs by utilizing the visual perception system's abilities to absorb large data quantities. This thesis examines the state of the art in security log usability, and proposes two ideas to the areas of security log usability and security visualization: First, we introduce LogWheels, an interactive dashboard offering remote monitoring of security incident logs, through a user friendly visualization interface. By offering three levels of granularity, LogWheels provides both an overview of the entire system, and the opportunity to request details on demand. Second, we introduce the incident wheel, the core visualization component of LogWheels. The incident wheel presents three key dimensions of security incidents -- 'what', 'when', and 'where' -- all within a single screen. In addition to a specification of LogWheels architecture and visualization scheme, the thesis is accompanied by a functional proof-of-concept, which allows demonstrations of the system on real or simulated security data.

Place, publisher, year, edition, pages
Institutt for telematikk , 2011. , 125 p.
Keyword [no]
ntnudaim:5898, MTDT datateknikk, Program- og informasjonssystemer
URN: urn:nbn:no:ntnu:diva-13832Local ID: ntnudaim:5898OAI: diva2:443564
Available from: 2011-09-26 Created: 2011-09-23 Last updated: 2013-06-23Bibliographically approved

Open Access in DiVA

fulltext(2438 kB)469 downloads
File information
File name FULLTEXT01.pdfFile size 2438 kBChecksum SHA-512
Type fulltextMimetype application/pdf
cover(47 kB)21 downloads
File information
File name COVER01.pdfFile size 47 kBChecksum SHA-512
Type coverMimetype application/pdf
attachment(82859 kB)1263 downloads
File information
File name ATTACHMENT01.zipFile size 82859 kBChecksum SHA-512
Type attachmentMimetype application/zip

By organisation
Department of Computer and Information Science

Search outside of DiVA

GoogleGoogle Scholar
Total: 469 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

Total: 98 hits
ReferencesLink to record
Permanent link

Direct link