Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
|
 |
A Scalable Aural-Visual Environment for Security Event Monitoring, Analysis, and Response
| |
|
A Scalable Aural-Visual Environment for Security Event Monitoring, Analysis, and Response
Paul Z. Kolano1 
| (1) |
NASA Advanced Supercomputing Division, NASA Ames Research Center, M/S 258-6, Moffett Field, CA 94035, U.S.A |
Abstract
Intrusion detection systems gather large quantities of host and network information in an attempt to detect and respond to
attacks against an organization. The widely varying nature of attacks makes humans essential for analysis, but the sheer volume
of data can quickly overwhelm even experienced analysts. Existing approaches utilize visualization to provide rapidly comprehensible
representations of the data, but fail to scale to real-world environments due to unrealistic data handling and lack of response
facilities. This paper introduces a new tool for security event monitoring, analysis, and response called Savors. Savors provides
suitable scalability by utilizing three additional areas of computing. High-end computing brings large amounts of on-demand
processing to bear on the problem. Auralization allows both monitoring and analysis to be performed in parallel. Finally,
grid computing provides the basis for remote data access and response capabilities with seamless and secure access to organization
resources.
This work is supported by the NASA Advanced Supercomputing Division under Task Order NNA05AC20T (Contract GS-09F-00282) with
Advanced Management Technology Inc.
Fulltext Preview (Small, Large)
 References secured to subscribers.
|
|
|
|
|
|