This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
2005 IEEE Workshops on Visualization for Computer Security
A User-centered Look at Glyph-based Security Visualization
Minneapolis, Minnesota
October 26-October 26
ISBN: 0-7803-9477-1
Anita Komlodi, University of Maryland Baltimore County
Penny Rheingans, University of Maryland Baltimore County
Utkarsha Ayachit, University of Maryland Baltimore County
John R. Goodall, University of Maryland Baltimore County
Amit Joshi, University of Maryland Baltimore County
This paper presents the Intrusion Detection toolkit (IDtk), an information Visualization tool for intrusion detection (ID). IDtk was developed through a user-centered design process, in which we identi- fied design guidelines to support ID users. ID analysts protect their networks by searching for evidence of attacks in ID system output, firewall and system logs, and other complex, textual data sources. Monitoring and analyzing these sources incurs a heavy cognitive load for analysts. The use of information visualization techniques offers a valuable addition to the toolkit of the ID analyst. Several visualization techniques for ID have been developed, but few usability or field studies have been completed to assess the needs of ID analysts and the usability and usefulness of these tools. We intended to fill this gap by applying a user-centered design process in the development and evaluation of IDtk, a 3D, glyph-based visualization tool that gives the user maximum flexibility in setting up how the visualization display represents ID data. The user can also customize whether the display is a simple, high-level overview to support monitoring, or a more complex 3D view allowing for viewing the data from multiple angles and thus supporting analysis and diagnosis. This flexibility was found crucial in our usability evaluation. In addition to describing the tool, we report the findings of our user evaluation and propose new guidelines for the design of information visualization tools for ID.
Index Terms:
information visualization, intrusion detection, glyphs,multivariate display
Citation:
Anita Komlodi, Penny Rheingans, Utkarsha Ayachit, John R. Goodall, Amit Joshi, "A User-centered Look at Glyph-based Security Visualization," vizsec, pp.3, 2005 IEEE Workshops on Visualization for Computer Security, 2005
Usage of this product signifies your acceptance of the Terms of Use.