|
Free Tool Paints Picture Of Stealthy Attacks |
|
|
|
Source: Dark Reading - Posted by anthony
|
The Honeynet Project has beefed up a free tool that helps spot attacks that can elude detection. The Picviz tool takes data from various log analysis sources and converts them into a multidimensional visual map of events.
Researchers have now added a graphical user interface to Picviz, which should make it easier to deploy and more attractive to a broader range of users. Picviz developers Sebastien Tricaud and Philippe Saade have published a paper (PDF) that details how Picviz works and how it gathers and renders data from traffic logs, database logs, SSH logs, syslogs, IPtables logs, Apache logs, and other sources.
Picviz's "parallel coordinates" approach represents an unlimited number of events in multiple dimensions, such as the protocol, URL, IP address, user agent, time frames, and other parameters. Parallel coordinates are multidimensional images used in aircraft collision-detection, as well as in other network tools. Picviz was developed to automate these images, according to Tricaud.
"Using parallel coordinates interactively makes finding issues rather natural and is very intuitive. Without a decent GUI, the program is only targeting a small set of people," says Tricaud, CTO of The Honeynet Project and chapter lead of the French Honeynet Project. The GUI and other features added to the tool make it more approachable to more users, he says.
Read this full article at Dark Reading
Only registered users can write comments. Please login or register. Powered by AkoComment! |