The Experts below are selected from a list of 48 Experts worldwide ranked by ideXlab platform

Jungsuk Song - One of the best experts on this subject based on the ideXlab platform.

  • Visualization of Security Event Logs across multiple networks and its application to a CSOC
    Cluster Computing, 2019
    Co-Authors: Boyeon Song, Jangwon Choi, Sang-soo Choi, Jungsuk Song
    Abstract:

    We introduce VisIDAC presented in Song at al (In: Nguyen, P.Q., Zhou, J. (eds.) Information Security—20th International Conference, ISC 2017, Security and CryptoLogy, vol. 10599. Springer International Publishing, 2017 ), which is a 3-D real-time visualization of Security Event Log collection detected by intrusion detection systems installed in multiple networks. VisIDAC consists of three parallel plane-squares which represent global source networks, target networks, and global destination networks. Security Events are displayed in different shapes, colors and spaces, according to their main features. It helps Security operators to immediately understand the key properties of Security Events. We also apply VisIDAC to a public cyber Security operations center, Science and TechnoLogy Cyber Security Center (S&T-CSC), and demonstrate its usefulness. VisIDAC allows users to grasp more intuitively the overall flow of Security Events and their trend, makes it easy to recognize large-scale Security Events such as network scanning, port scanning, and distributed denial of service attacks, and is also effective to distinguish Security Event types: which target network they are related to; whether they are inbound or outbound traffic; whether they are momentary or continuous; and what protocol and port number are mainly used.

  • Visualization of Security Event Logs across multiple networks and its application to a CSOC
    Cluster Computing, 2017
    Co-Authors: Boyeon Song, Jangwon Choi, Sang-soo Choi, Jungsuk Song
    Abstract:

    We introduce VisIDAC presented in Song at al (In: Nguyen, P.Q., Zhou, J. (eds.) Information Security—20th International Conference, ISC 2017, Security and CryptoLogy, vol. 10599. Springer International Publishing, 2017), which is a 3-D real-time visualization of Security Event Log collection detected by intrusion detection systems installed in multiple networks. VisIDAC consists of three parallel plane-squares which represent global source networks, target networks, and global destination networks. Security Events are displayed in different shapes, colors and spaces, according to their main features. It helps Security operators to immediately understand the key properties of Security Events. We also apply VisIDAC to a public cyber Security operations center, Science and TechnoLogy Cyber Security Center (ST whether they are inbound or outbound traffic; whether they are momentary or continuous; and what protocol and port number are mainly used.

Boyeon Song - One of the best experts on this subject based on the ideXlab platform.

  • Visualization of Security Event Logs across multiple networks and its application to a CSOC
    Cluster Computing, 2019
    Co-Authors: Boyeon Song, Jangwon Choi, Sang-soo Choi, Jungsuk Song
    Abstract:

    We introduce VisIDAC presented in Song at al (In: Nguyen, P.Q., Zhou, J. (eds.) Information Security—20th International Conference, ISC 2017, Security and CryptoLogy, vol. 10599. Springer International Publishing, 2017 ), which is a 3-D real-time visualization of Security Event Log collection detected by intrusion detection systems installed in multiple networks. VisIDAC consists of three parallel plane-squares which represent global source networks, target networks, and global destination networks. Security Events are displayed in different shapes, colors and spaces, according to their main features. It helps Security operators to immediately understand the key properties of Security Events. We also apply VisIDAC to a public cyber Security operations center, Science and TechnoLogy Cyber Security Center (S&T-CSC), and demonstrate its usefulness. VisIDAC allows users to grasp more intuitively the overall flow of Security Events and their trend, makes it easy to recognize large-scale Security Events such as network scanning, port scanning, and distributed denial of service attacks, and is also effective to distinguish Security Event types: which target network they are related to; whether they are inbound or outbound traffic; whether they are momentary or continuous; and what protocol and port number are mainly used.

  • Visualization of Security Event Logs across multiple networks and its application to a CSOC
    Cluster Computing, 2017
    Co-Authors: Boyeon Song, Jangwon Choi, Sang-soo Choi, Jungsuk Song
    Abstract:

    We introduce VisIDAC presented in Song at al (In: Nguyen, P.Q., Zhou, J. (eds.) Information Security—20th International Conference, ISC 2017, Security and CryptoLogy, vol. 10599. Springer International Publishing, 2017), which is a 3-D real-time visualization of Security Event Log collection detected by intrusion detection systems installed in multiple networks. VisIDAC consists of three parallel plane-squares which represent global source networks, target networks, and global destination networks. Security Events are displayed in different shapes, colors and spaces, according to their main features. It helps Security operators to immediately understand the key properties of Security Events. We also apply VisIDAC to a public cyber Security operations center, Science and TechnoLogy Cyber Security Center (ST whether they are inbound or outbound traffic; whether they are momentary or continuous; and what protocol and port number are mainly used.

Sang-soo Choi - One of the best experts on this subject based on the ideXlab platform.

  • Visualization of Security Event Logs across multiple networks and its application to a CSOC
    Cluster Computing, 2019
    Co-Authors: Boyeon Song, Jangwon Choi, Sang-soo Choi, Jungsuk Song
    Abstract:

    We introduce VisIDAC presented in Song at al (In: Nguyen, P.Q., Zhou, J. (eds.) Information Security—20th International Conference, ISC 2017, Security and CryptoLogy, vol. 10599. Springer International Publishing, 2017 ), which is a 3-D real-time visualization of Security Event Log collection detected by intrusion detection systems installed in multiple networks. VisIDAC consists of three parallel plane-squares which represent global source networks, target networks, and global destination networks. Security Events are displayed in different shapes, colors and spaces, according to their main features. It helps Security operators to immediately understand the key properties of Security Events. We also apply VisIDAC to a public cyber Security operations center, Science and TechnoLogy Cyber Security Center (S&T-CSC), and demonstrate its usefulness. VisIDAC allows users to grasp more intuitively the overall flow of Security Events and their trend, makes it easy to recognize large-scale Security Events such as network scanning, port scanning, and distributed denial of service attacks, and is also effective to distinguish Security Event types: which target network they are related to; whether they are inbound or outbound traffic; whether they are momentary or continuous; and what protocol and port number are mainly used.

  • Visualization of Security Event Logs across multiple networks and its application to a CSOC
    Cluster Computing, 2017
    Co-Authors: Boyeon Song, Jangwon Choi, Sang-soo Choi, Jungsuk Song
    Abstract:

    We introduce VisIDAC presented in Song at al (In: Nguyen, P.Q., Zhou, J. (eds.) Information Security—20th International Conference, ISC 2017, Security and CryptoLogy, vol. 10599. Springer International Publishing, 2017), which is a 3-D real-time visualization of Security Event Log collection detected by intrusion detection systems installed in multiple networks. VisIDAC consists of three parallel plane-squares which represent global source networks, target networks, and global destination networks. Security Events are displayed in different shapes, colors and spaces, according to their main features. It helps Security operators to immediately understand the key properties of Security Events. We also apply VisIDAC to a public cyber Security operations center, Science and TechnoLogy Cyber Security Center (ST whether they are inbound or outbound traffic; whether they are momentary or continuous; and what protocol and port number are mainly used.

Jangwon Choi - One of the best experts on this subject based on the ideXlab platform.

  • Visualization of Security Event Logs across multiple networks and its application to a CSOC
    Cluster Computing, 2019
    Co-Authors: Boyeon Song, Jangwon Choi, Sang-soo Choi, Jungsuk Song
    Abstract:

    We introduce VisIDAC presented in Song at al (In: Nguyen, P.Q., Zhou, J. (eds.) Information Security—20th International Conference, ISC 2017, Security and CryptoLogy, vol. 10599. Springer International Publishing, 2017 ), which is a 3-D real-time visualization of Security Event Log collection detected by intrusion detection systems installed in multiple networks. VisIDAC consists of three parallel plane-squares which represent global source networks, target networks, and global destination networks. Security Events are displayed in different shapes, colors and spaces, according to their main features. It helps Security operators to immediately understand the key properties of Security Events. We also apply VisIDAC to a public cyber Security operations center, Science and TechnoLogy Cyber Security Center (S&T-CSC), and demonstrate its usefulness. VisIDAC allows users to grasp more intuitively the overall flow of Security Events and their trend, makes it easy to recognize large-scale Security Events such as network scanning, port scanning, and distributed denial of service attacks, and is also effective to distinguish Security Event types: which target network they are related to; whether they are inbound or outbound traffic; whether they are momentary or continuous; and what protocol and port number are mainly used.

  • Visualization of Security Event Logs across multiple networks and its application to a CSOC
    Cluster Computing, 2017
    Co-Authors: Boyeon Song, Jangwon Choi, Sang-soo Choi, Jungsuk Song
    Abstract:

    We introduce VisIDAC presented in Song at al (In: Nguyen, P.Q., Zhou, J. (eds.) Information Security—20th International Conference, ISC 2017, Security and CryptoLogy, vol. 10599. Springer International Publishing, 2017), which is a 3-D real-time visualization of Security Event Log collection detected by intrusion detection systems installed in multiple networks. VisIDAC consists of three parallel plane-squares which represent global source networks, target networks, and global destination networks. Security Events are displayed in different shapes, colors and spaces, according to their main features. It helps Security operators to immediately understand the key properties of Security Events. We also apply VisIDAC to a public cyber Security operations center, Science and TechnoLogy Cyber Security Center (ST whether they are inbound or outbound traffic; whether they are momentary or continuous; and what protocol and port number are mainly used.

Simon Parkinson - One of the best experts on this subject based on the ideXlab platform.

  • Eliciting and utilising knowledge for Security Event Log analysis: An association rule mining and automated planning approach
    Expert Systems with Applications, 2018
    Co-Authors: Saad Khan, Simon Parkinson
    Abstract:

    Abstract Vulnerability assessment and Security configuration activities are heavily reliant on expert knowledge. This requirement often results in many systems being left insecure due to a lack of analysis expertise and access to specialist resources. It has long been known that a system’s Event Logs provide historical information depicting potential Security breaches, as well as recording configuration activities. However, identifying and utilising knowledge within the Event Logs is challenging for the non-expert. In this paper, a novel technique is developed to process Security Event Logs of a computer that has been assessed and configured by a Security professional, extract key domain knowledge indicative of their expert decision making, and automatically apply learnt knowledge to previously unseen systems by non-experts. The technique converts Event Log entries into an object-based model and dynamically extracts associative rules. The rules are further improved in terms of quality using a temporal metric to autonomously establish temporal-association rules and acquire a domain model of expert configuration tasks. The acquired domain model and problem instance generated from a previously unseen system can then be used to produce a plan-of-action, which can be exploited by non-professionals to improve their system’s Security. Empirical analysis is subsequently performed on 20 Event Logs, where identified plan traces are discussed in terms of accuracy and performance.