Applied Security Visualization

Applied Security Visualization
复制标题

DOI:
--
复制
发表时间:
2008-08
期刊:
Proceedings from the Sixth Annual IEEE SMC Information Assurance Workshop
影响因子:
--
通讯作者:
R. Marty
R. Marty
中科院分区:
其他
文献类型:
--
作者:
R. Marty

文献摘要

被引文献

相似文献

应用安全可视化收集日志数据是一回事,拥有相关信息是另一回事。将各种日志数据转换为有意义的安全信息的艺术是本书的核心。Raffy以一种直截了当的方式,并通过实际操作的例子,说明了如何掌握这样的挑战。让我们得到启发。诺华全球IT安全主管Andreas Wuchner使用可视化保护您的网络免受最棘手、最隐蔽的威胁随着网络变得越来越复杂,保护它们变得越来越困难。解决方案是可视化。使用当今最先进的数据可视化技术,您可以更深入地了解网络上正在发生的事情。您可以发现隐藏的数据模式,识别新出现的漏洞和攻击,并果断地采取比传统方法更有可能成功的对策。在《应用安全可视化》中,领先的网络安全可视化专家Raffael Marty介绍了在网络上使用可视化所需的所有概念、技术和工具。您将学习如何识别和利用正确的数据源,然后将您的数据转换为显示您真正需要知道的内容的视觉效果。接下来,Marty展示了如何使用可视化来执行广泛的网络安全分析,评估特定的威胁,甚至提高业务合规性。最后,他介绍了一组广泛的可视化工具。这本书的CD还包括DAVIX,一个免费提供的安全可视化工具的汇编。您将学习如何:深入了解对有效可视化至关重要的数据源为您的IT数据选择最合适的图表和技术将复杂数据转换为清晰的可视化表示形式迭代图表,为采取行动提供更好的洞察力评估网络边界威胁,以及内部人员施加的威胁使用可视化更成功地管理风险和合规性要求信息和网络安全的组织方面比较和掌握当今最有用的安全可视化工具包含实时CD Data Analysis and Visualization Linux(DAVIX)。DAVIX是一个强大的工具汇编,用于可视化网络和评估其安全性。DAVIX直接从CD-ROM运行,无需安装。Raffael Marty是Splunk的首席安全策略师和高级产品经理,Splunk是IT基础设施大规模高速索引和搜索技术的领先提供商。作为客户倡导者和监护人,他专注于使用他在数据可视化,日志管理,入侵检测和合规性方面的技能。Marty是CEE(公共事件表达式)和OVAL(开放漏洞和评估语言)等行业标准委员会的积极参与者,他创建了Thor和AfterGlow自动化工具,并创建了安全可视化门户secviz. org。在加入Splunk之前,他管理ArcSight的解决方案团队,担任PriceWaterhouseCoopers的IT安全顾问,并且是IBM Research全球安全分析实验室的成员。
APPLIED SECURITY VISUALIZATION Collecting log data is one thing, having relevant information is something else. The art to transform all kinds of log data into meaningful security information is the core of this book. Raffy illustrates in a straight forward way, and with hands-on examples, how such a challenge can be mastered. Let's get inspired. Andreas Wuchner, Head of Global IT Security, Novartis Use Visualization to Secure Your Network Against the Toughest, Best-Hidden Threats As networks become ever more complex, securing them becomes more and more difficult. The solution is visualization. Using todays state-of-the-art data visualization techniques, you can gain a far deeper understanding of whats happening on your network right now. You can uncover hidden patterns of data, identify emerging vulnerabilities and attacks, and respond decisively with countermeasures that are far more likely to succeed than conventional methods. In Applied Security Visualization, leading network security visualization expert Raffael Marty introduces all the concepts, techniques, and tools you need to use visualization on your network. Youll learn how to identify and utilize the right data sources, then transform your data into visuals that reveal what you really need to know. Next, Marty shows how to use visualization to perform broad network security analyses, assess specific threats, and even improve business compliance. He concludes with an introduction to a broad set of visualization tools. The books CD also includes DAVIX, a compilation of freely available tools for security visualization. You'll learn how to: Intimately understand the data sources that are essential for effective visualization Choose the most appropriate graphs and techniques for your IT data Transform complex data into crystal-clear visual representations Iterate your graphs to deliver even better insight for taking action Assess threats to your network perimeter, as well as threats imposed by insiders Use visualization to manage risks and compliance mandates more successfully Visually audit both the technical and organizational aspects of information and network security Compare and master todays most useful tools for security visualization Contains the live CD Data Analysis and Visualization Linux (DAVIX). DAVIX is a compilation of powerful tools for visualizing networks and assessing their security. DAVIX runs directly from the CD-ROM, without installation. Raffael Marty is chief security strategist and senior product manager for Splunk, the leading provider of large-scale, high-speed indexing and search technology for IT infrastructures. As customer advocate and guardian, he focuses on using his skills in data visualization, log management, intrusion detection, and compliance. An active participant on industry standards committees such as CEE (Common Event Expression) and OVAL (Open Vulnerability and Assessment Language), Marty created the Thor and AfterGlow automation tools, and founded the security visualization portal secviz.org. Before joining Splunk, he managed the solutions team at ArcSight, served as IT security consultant for PriceWaterhouseCoopers, and was a member of the IBM Research Global Security Analysis Lab.