A Study on Efficient Log Visualization Using D3 Component against APT: How to Visualize Security Logs Efficiently?

Jaehee Lee, Jinhyeok Jeon, Changyeob Lee, Junbeom Lee, Jaebin Cho, Kyungho Lee

Research output: Chapter in Book/Report/Conference proceedingConference contribution

9 Citations (Scopus)

Abstract

APT attack has caused chaos in society since 2006. Especially, the vulnerability of the infrastructure is exposed to the outside a lot due to the development of the IT infrastructure in Korea. In addition, APT attacks targeting companies' major confidential information are increasing every year. APT attack causes negative publicity for the company and financial damage. APT is completely different from the problem which most organizations have been dealt with. Cyber-attack threats were visible in the past. But currently, APT attacks were invisible and focused on confidential data. Therefore, we need a new approach to solve this problem. We have to find traces of prejudice in the circumstances, everything seems normal. If we perform a correlation analysis of the log acquired from all the devices, systems and applications, we can easily understand the problems which occur in our information systems. Current commercial SIEM has the ability to visualize the correlation analysis and the log. But the security officer takes a lot of time to understand the visualized security logs. Moreover, due to expensive cost of SIEM solution, small companies have difficulty introducing SIEM solution. For these reasons, we have developed a SIEM solution based on open-source program such as D3 component which results in decreasing the cost of the program. In addition, we analyzed the D3 components which can visualize the security logs, and matched D3 components with the security logs. In this paper, we propose the visualization methods using D3 components for analyzing the security logs efficiently.

Original languageEnglish
Title of host publication2016 International Conference on Platform Technology and Service, PlatCon 2016 - Proceedings
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781467386852
DOIs
Publication statusPublished - 2016 Apr 19
Event3rd International Conference on Platform Technology and Service, PlatCon 2016 - Jeju, Korea, Republic of
Duration: 2016 Feb 152016 Feb 17

Publication series

Name2016 International Conference on Platform Technology and Service, PlatCon 2016 - Proceedings

Other

Other3rd International Conference on Platform Technology and Service, PlatCon 2016
Country/TerritoryKorea, Republic of
CityJeju
Period16/2/1516/2/17

Keywords

  • APT
  • Bigdata Visualization
  • D3 component
  • Log correlation analysis
  • Log visualization
  • SIEM

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Computer Science Applications
  • Information Systems

Fingerprint

Dive into the research topics of 'A Study on Efficient Log Visualization Using D3 Component against APT: How to Visualize Security Logs Efficiently?'. Together they form a unique fingerprint.

Cite this