Paper
3 February 2014 VAFLE: visual analytics of firewall log events
Mohammad Ghoniem, Georgiy Shurkhovetskyy, Ahmed Bahey, Benoît Otjacques
Author Affiliations +
Proceedings Volume 9017, Visualization and Data Analysis 2014; 901704 (2014) https://doi.org/10.1117/12.2037790
Event: IS&T/SPIE Electronic Imaging, 2014, San Francisco, California, United States
Abstract
In this work, we present VAFLE, an interactive network security visualization prototype for the analysis of firewall log events. Keeping it simple yet effective for analysts, we provide multiple coordinated interactive visualizations augmented with clustering capabilities customized to support anomaly detection and cyber situation awareness. We evaluate the usefulness of the prototype in a use case with network traffic datasets from previous VAST Challenges, illustrating its effectiveness at promoting fast and well-informed decisions. We explain how a security analyst may spot suspicious traffic using VAFLE. We further assess its usefulness through a qualitative evaluation involving network security experts, whose feedback is reported and discussed.
© (2014) COPYRIGHT Society of Photo-Optical Instrumentation Engineers (SPIE). Downloading of the abstract is permitted for personal use only.
Mohammad Ghoniem, Georgiy Shurkhovetskyy, Ahmed Bahey, and Benoît Otjacques "VAFLE: visual analytics of firewall log events", Proc. SPIE 9017, Visualization and Data Analysis 2014, 901704 (3 February 2014); https://doi.org/10.1117/12.2037790
Lens.org Logo
CITATIONS
Cited by 11 scholarly publications.
Advertisement
Advertisement
RIGHTS & PERMISSIONS
Get copyright permission  Get copyright permission on Copyright Marketplace
KEYWORDS
Visualization

Network security

Visual analytics

Computer security

Information security

Forensic science

Inspection

Back to Top