VISNU: A Novel Visualization Methodology of Security Events Optimized for a Centralized SOC

Taewoong Kwon,Jungsuk Song,Sang-soo Choi,Yunsoo Lee,Jinhak Park

Published 2018 in Asia Joint Conference on Information Security

ABSTRACT

Intrusion detection system(IDS) is one of the most powerful security devices in order to monitor cyber threats happening on the network. Since IDS raises an extremely large number of alerts (hereafter refered to as 'security events'), security experts are unable to analyze all of them in real time. To make matters worse, most of IDS provide only text-based information for the security events. In order to cope with this limitation, many approaches have been proposed on visualizing the security events. Since the existing visualization approaches focus on only a single organization, in many cases, they are not suitable for a centralized security operation center (CSOC) which is in charging of monitoring many organizations. In this paper, we propose a novel visualization VISualization system for finding out Network based Underneath attacks (VISNU) which can help security experts of the CSOC to analyze the security events more effectively. To this end, the VISNU classifies the security events according to each organization and displays them based on both real time and accumulated information such as the appreance patterns and their history, etc. The experimental results demonstrated that it is very useful for finding out an abnormal activites from the security events and provides better understandings and insights for analyzing them.

PUBLICATION RECORD

CITATION MAP

EXTRACTION MAP

CLAIMS

  • No claims are published for this paper.

CONCEPTS

  • No concepts are published for this paper.

REFERENCES

Showing 1-20 of 20 references · Page 1 of 1