A Statistical Comparison of Security Visualization Efficiency Compared to Manual Analysis of IDS Log Data
David Freet, Rajeev K. Agrawal · 2018
For the security and identification of threats to computer network systems, system log files play a critical role in allowing system administrators to monitor and respond to security incidents. However, as threats continue to increase in size and complexity, the amount of raw data generated by intrusion detection systems (IDS) can quickly overwhelm security analysts who are tasked with sorting through the data in order to identify malicious traffic patterns. Security visualization provides big picture context for activities identified by the IDS as potentially malicious and this can then direct the analyst to view a smaller number of packets at a more granular level. The results of this research will show that there is a measurable gain in analyst performance using security visualization as compared to manually analyzing network data at the packet level alone.