首页> 外文会议>International Conference on Platform Technology and Service >A Study on Efficient Log Visualization Using D3 Component against APT: How to Visualize Security Logs Efficiently?
【24h】

A Study on Efficient Log Visualization Using D3 Component against APT: How to Visualize Security Logs Efficiently?

机译:使用针对APT的D3组件进行有效日志可视化的研究:如何有效地可视化安全日志?

获取原文

摘要

APT attack has caused chaos in society since 2006. Especially, the vulnerability of the infrastructure is exposed to the outside a lot due to the development of the IT infrastructure in Korea. In addition, APT attacks targeting companies' major confidential information are increasing every year. APT attack causes negative publicity for the company and financial damage. APT is completely different from the problem which most organizations have been dealt with. Cyber-attack threats were visible in the past. But currently, APT attacks were invisible and focused on confidential data. Therefore, we need a new approach to solve this problem. We have to find traces of prejudice in the circumstances, everything seems normal. If we perform a correlation analysis of the log acquired from all the devices, systems and applications, we can easily understand the problems which occur in our information systems. Current commercial SIEM has the ability to visualize the correlation analysis and the log. But the security officer takes a lot of time to understand the visualized security logs. Moreover, due to expensive cost of SIEM solution, small companies have difficulty introducing SIEM solution. For these reasons, we have developed a SIEM solution based on open-source program such as D3 component which results in decreasing the cost of the program. In addition, we analyzed the D3 components which can visualize the security logs, and matched D3 components with the security logs. In this paper, we propose the visualization methods using D3 components for analyzing the security logs efficiently.
机译:自2006年以来,APT攻击已在社会上引起混乱。特别是,由于韩国IT基础设施的发展,基础设施的脆弱性暴露在外部。此外,针对公司主要机密信息的APT攻击每年都在增加。 APT攻击会对公司造成负面影响,并造成财务损失。 APT与大多数组织已经解决的问题完全不同。过去可以看到网络攻击威胁。但是目前,APT攻击是不可见的,并且集中在机密数据上。因此,我们需要一种新的方法来解决此问题。在这种情况下,我们必须找到偏见的痕迹,一切似乎都很正常。如果我们对从所有设备,系统和应用程序获取的日志进行相关分析,则我们可以轻松了解信息系统中出现的问题。当前的商业SIEM具有可视化相关性分析和日志的能力。但是安全人员需要花费大量时间来了解可视化的安全日志。此外,由于SIEM解决方案的昂贵成本,小公司很难引入SIEM解决方案。由于这些原因,我们已经开发了基于开源程序(例如D3组件)的SIEM解决方案,从而降低了程序成本。此外,我们分析了可以可视化安全日志的D3组件,并将D3组件与安全日志进行了匹配。在本文中,我们提出了使用D3组件的可视化方法,以有效地分析安全日志。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号