Home > Security News > Security visualization helps make log files work
Security News:
EMAIL THIS

Security visualization helps make log files work

By Robert Westervelt, News Editor
28 Aug 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Many companies are required to keep certain log files detailing important system events, but until now, most firms haven't been properly analyzing them, if they analyze them at all.

If there were more tools out there to make this easier I think a lot more people would actually use visualization.
Raffael Marty,
author, Applied Security Visualization

One researcher is trying to make the data easier to use. Raffael Marty, a security expert with log management firm Splunk Inc., wrote Applied Security Visualization, a book trumpeting the advantage of using sophisticated charts and graphs to better view log data. The book debuted earlier this month at the Black Hat briefings in Las Vegas.

"If you look at log files or system events to understand what is going on in your machines or in your network, a lot of people look at their textual logs. … and the problem is you have 100,000 lines or more so it's really hard to figure out what's happening in that data," Marty said. "If you generate a picture from that data you very quickly can see what is going on in there."

The goal is to take network traffic, intrusion defense system and firewall data and begin visualizing pieces of it to create an overall picture of the company's security posture. When you start developing the appropriate chart or graph to better flesh out the data, you can begin to see patterns and sometimes certain pieces of information stand out, Marty said.

Listen to the interview with Raffael Marty:
Security Wire Weekly: Security Visualization

Raffael Marty, author of Applied Security Visualization, talks about how security visualization techniques can help improve security decisions. Marty is chief security strategist at log analysis vendor Splunk.

Download MP3 | Subscribe to Security Wire Weekly

The field of security visualization is still relatively immature and needs much more research, Marty said. Few tools are available to use visualization in a security investigation.

"If there were more tools out there to make this easier I think a lot more people would actually use visualization," Marty said.

If you have millions or even thousands of log files to visualize it can get tricky, Marty said. Companies need to have a solid handle on the data they're collecting and security pros need to understand the entries to a certain degree, Marty said. Firewall log files would be useless with little domain expertise on staff to help generate graphs.

Marty has released a Linux CD called Data Analysis and Visualization Linux (DAVIX). The build is based on the SLAX distribution and includes some free tools for data processing and visualization. Marty also created a log file analysis tool called AfterGlow, which generates event graphs and treemaps.

To get the best results, log data needs to be filtered down and clustered together, Marty said.

SearchSecurity radio:

"With firewall log files, you don't need to know what specific IP address is connecting to me from the outside," Marty said. "You can cluster it to get a general idea of what happened and then if you want to drill down you can open up that cluster."

Visualization could be used to build dashboards for a company compliance program, Marty said. For example, a chart or graph could help visualize violations per Payment Card Industry Data Security Standard (PCI DSS) requirement, helping companies determine where they fall short of the standard. To meet Sarbanes-Oxley (SOX), some firms could get value out of visualizing the traffic going to the server hosting the company's financial data.

Marty said visualization can be an important tool in finding database violations in real-time event data. It can be used to audit large database management systems, such as Oracle and Microsoft's SQL-Server to figure out who accessed a particular table, and whether the database table was altered.

"If you correlate it to the users you can find violations very quickly," Marty said.



Tags: Vulnerability Risk AssessmentPCI Data Security StandardSarbanes-Oxley ActHIPAAEnterprise Risk Management: Metrics and AssessmentsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Vulnerability Risk Assessment
Are Web application penetration tests still important?
McAfee to acquire Solidcore Systems for whitelisting
The Pipe Dream of No More Free Bugs
Vulnerability test methods for application security assessments
Free HP SWFScan tool detects Adobe Flash flaws
PCI QSA assurance program penalizes assessors
Information security book excerpts and reviews
New York drafts language demanding secure code
Security experts identify 25 dangerous coding errors
Microsoft Windows XML flaw exploits test desktop antimalware
Vulnerability Risk Assessment Research

PCI Data Security Standard
PCI management: The case for Web application firewalls
MasterCard increases PCI compliance requirements for some merchants
PCI compliance requirement 1: Firewalls
PCI compliance requirement 2: Defaults
PCI compliance requirement 5: Antivirus
PCI compliance requirement 4: Encrypt transmissions
PCI compliance requirement 3: Protect data
PCI compliance requirement 6: Systems and applications
PCI compliance requirement 8: Unique IDs
PCI compliance requirement 10: Auditing

Sarbanes-Oxley Act
Ex-SEC chief Pitt decries state of Sarbanes-Oxley, risk management
Information security book excerpts and reviews
Internal audits for Sarbanes Oxley and internal IT support
Internal auditors and CISOs mitigate similar risks
Implement security and compliance in a risk management context
Does password sharing in international branches violate SOX?
Consensus Controls project aims to set benchmarks for compliance
The Little Black Book of Computer Security, 2nd Edition
RSA attendees see data classification, rights management projects stumble
Hannaford breach illustrates dangerous compliance mentality
Sarbanes-Oxley Act Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
gray hat  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts