<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">

<head>
  <title>SecViz | Security Visualization and Intelligence</title>
  <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<link rel="alternate" type="application/rss+xml" title="SecViz RSS" href="rss.xml" />

<link rel="shortcut icon" href="themes/bluebreeze/favicon.ico" type="image/x-icon" />
  <style type="text/css" media="all">@import "files/css/50087fea75508f42020400e10082e589.css";</style>
  <script type="text/javascript" src="misc/jquery.js"></script>
<script type="text/javascript" src="misc/drupal.js"></script>
<script type="text/javascript">Drupal.extend({ settings: { "googleanalytics": { "trackOutgoing": 1, "trackMailto": 1, "trackDownload": 1, "trackDownloadExtensions": "7z|aac|avi|csv|doc|exe|flv|gif|gz|jpe?g|js|mp(3|4|e?g)|mov|pdf|phps|png|ppt|rar|sit|tar|torrent|txt|wma|wmv|xls|xml|zip", "LegacyVersion": 0 } } });</script>
  <script type="text/javascript"> </script>
  </head>

<body id="home">
  <div id="page" class="">
  
    <div id="header">
    
      <div id="logo-title">
       
                  <a href="index.html" title="Home">
            <img src="files/bluebreeze_logo.png" alt="Home" id="logo" />
          </a>
                
                
                
      </div>
      <div style="padding: 50px 3px; float:right">
	  <a href="http://pixlcloud.com"><img border=0 width=100 style="padding-top:5px; padding-right:5px;" alt="Powered by PixlCloud" src="files/powered.png"></a>
      </div>
     
      
      <div class="menu withprimary ">
                      <div id="primary" class="clear-block">
              <ul class="links-menu">
<li><a href="content/applied-security-visualization.html">Book</a></li>
<li><a href="category/image-galleries/graph-exchange.html">Graphs</a></li>
<li><a href="content/the-davix-live-cd.html" title="Data Analysis and VIsualisation uniX (DAVIX) is a live CD that contains a set of visualization tools that are readily usable for">DAVIX</a></li>
<li><a href="content/about.html">About</a></li>
</ul>            </div>
                    
                </div>
      
            
    </div>

    <div id="container" class=" ">
      
      <div id="main-wrapper">
      <div id="main" class="clear-block">
                        <div id="content-top"><div class="block block-block" id="block-block-3">
  <div class="blockinner">

    <h2 class="title">  </h2>

    <div class="content">
      <p>&nbsp;</p>
<center>
    <font size=7><A HREF="category/image-galleries/graph-exchange.html"><B>Gallery</B></A></font>
</center>
<p>&nbsp;</p>
    </div>
    
  </div>
</div>
</div>                                        <div class="node" id="node-1156">
      <h2 class="title">
      <a href="content/mapping-dns-with-graphviz.html">Mapping DNS with Graphviz</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted February 17th, 2018 by hackertarget</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_1"><a href="category/image-galleries/graph-exchange.html" rel="tag" title="This is the place where you can share your graphs." class="taxonomy_term_1">Graph Exchange</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <a href="content/mapping-dns-with-graphviz.html"><img src="files/images/domain-profiler-example.thumbnail.png" alt="Mapping DNS with Graphviz" title="Mapping DNS with Graphviz"  class="image image-thumbnail " width="150" height="105" /></a><p><a href="https://hackertarget.com/domain-profiler/">Mapping the DNS of an organization</a> on the fly using <strong>Graphviz</strong>. DNS data is collated using regular DNS lookups as well as passive data sets for sub-domains. Map includes IP, Hostname, Netblock Owner and record type.</p>
  </div>
  
    
</div>
<div class="node" id="node-1155">
      <h2 class="title">
      <a href="content/ai-and-ml-cyber-security-and-what-does-that-have-to-do-with-visualization.html">AI and ML in Cyber Security - And What Does That Have To Do With Visualization?</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted January 15th, 2018 by raffy</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_3"><a href="news.html" rel="tag" title="This is where you can start discussions around security visualization topics. Add your own entry and have people make comments." class="taxonomy_term_3">Discussion Entries</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <p>Adjacent to data visualization are all the different disciplines that help us getting from  raw data to  visualizations. There are the topics of <a href="http://raffy.ch/blog/2017/12/06/an-incomplete-security-big-data-history/">big data</a>, data mining, and data exploration which come to mind. The world has gotten quite confused and lax about using the terms artificial intelligence and machine learning. Often data mining, for example will be lumped underneath these topics. I have written a few pieces lately that talk about <a href="http://raffy.ch/blog/2018/01/14/ai-in-cyber-security-where-we-stand-where-we-need-to-go/">AI and ML in cyber security</a>. They should help bringing a bit more clarity into the approaches and what is suited for the cyber discussion. The topic of data visualization is still a crucial one and I am not doing it justice in any of my write ups. But we shouldn't forget that data visualization is probably one of the most important methods when it comes to helping analysts better understand what they are looking at, and helping data scientists understand what their algorithms have just done.</p>
<p>Oh, and should you be interested in Virtual Reality - I just published a short <a href="http://raffy.ch/blog/2018/01/17/virtual-reality-in-cyber-security/">critique of a 'pro VR'</a> article.</p>
  </div>
  
    
</div>
<div class="node" id="node-1154">
      <h2 class="title">
      <a href="content/network-attack-map-collection.html">Network Attack Map Collection</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted January 14th, 2018 by raffy</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_3"><a href="news.html" rel="tag" title="This is where you can start discussions around security visualization topics. Add your own entry and have people make comments." class="taxonomy_term_3">Discussion Entries</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <p>Found a nice collection of <a href="http://maps-us.bid/network-attack-map.html">network attack maps</a>. </p>
<p><a href="http://maps-us.bid/network-attack-map.html"><img src="files/images/Screen&#32;Shot&#32;2018-01-14&#32;at&#32;1.38.37&#32;PM.png"></a></p>
  </div>
  
    
</div>
<div class="node" id="node-1152">
      <h2 class="title">
      <a href="content/delivering-security-insights-with-data-analytics-and-visualization.html">Delivering Security Insights with Data Analytics and Visualization</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted December 8th, 2017 by raffy</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_3"><a href="news.html" rel="tag" title="This is where you can start discussions around security visualization topics. Add your own entry and have people make comments." class="taxonomy_term_3">Discussion Entries</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <p>In early December, I gave the <a href="http://bit.ly/2AXT6pG">keynote</a> at the <a href="http://acsac.org">ACSAC 2017</a> conference in Orlando, Florida. </p>
<p><center><img src="files/images/Screen&#32;Shot&#32;2017-12-08&#32;at&#32;11.17.02&#32;AM.preview.png" width="500"></center></p>
<p>In the presentation I look at a number of topics around using big data for security. I start by showing what big data looks like for security, how the <a href="http://raffy.ch/blog/2017/12/06/an-incomplete-security-big-data-history/">history of using security for big data</a> is tightly linked to the progress in big data itself. I talk about machine learning and artificial intelligence and show some of the limits and dangers of how we currently apply machine learning in security and how we can apply data visualization to help analysts better understand data. I then go on to peek a little bit into my magic 8 ball to see how security big data environments might look in the future and finish the presentation with posing a few challenges to the community about security for big data problems.</p>
  </div>
  
    
</div>
<div class="node" id="node-1149">
      <h2 class="title">
      <a href="content/eevi-evaluating-effectiveness-visualisation-cyber-security.html"> EEVi- Evaluating the Effectiveness of Visualisation in Cyber-Security</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted April 19th, 2017 by aneeshasethi</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_3"><a href="news.html" rel="tag" title="This is where you can start discussions around security visualization topics. Add your own entry and have people make comments." class="taxonomy_term_3">Discussion Entries</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <p>Hi all, </p>
<p>I am a PhD researcher at University of Southampton and my PhD topic is Visualisation in Cyber Security.</p>
<p>I have a questionnaire, for my thesis, aimed at people who have experience in Cyber Security, Visualization (or HCI) design or both. I would really appreciate if you can take some time out and fill out the questionnaire. </p>
<p>Please refer to the link below for more information or contact me. :)</p>
<p>https://www.isurvey.soton.ac.uk/23438</p>
<p>Thank you.<br />
Aneesha Sethi<br />
Aneesha.Sethi@soton.ac.uk</p>
  </div>
  
    
</div>
<div class="node" id="node-1147">
      <h2 class="title">
      <a href="content/security-analytics-visualization-big-data-workshop-black-hat-2017.html">Security Analytics - Visualization - Big Data Workshop Black Hat 2017</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted February 11th, 2017 by raffy</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_3"><a href="news.html" rel="tag" title="This is where you can start discussions around security visualization topics. Add your own entry and have people make comments." class="taxonomy_term_3">Discussion Entries</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <p><center><a href="http://ubm.io/2khLkKR"><br />
<h2>VISUAL ANALYTICS – DELIVERING ACTIONABLE SECURITY INTELLIGENCE</h2>
<p></a></center></p>
<p><center><br />
<h2>BlackHat 2017 - Las Vegas</H2><br />
<strong>Big Data is Getting Bigger - Visualization is Getting Easier - Learn How!</strong><br />
Dates: July 22-23 &amp; 24-25<br />
Location: Las Vegas, USA</br><br />
<font size=+3><a href="http://ubm.io/2khLkKR">SIGN UP NOW</a></font><br />
</center></p>
<p></br></p>
<p><center><iframe width="560" height="315" src="https://www.youtube.com/embed/hhISnNVV7LA" frameborder="0" allowfullscreen></iframe></center></p>
<h3>OVERVIEW</h3>
<p><a href="files/images/graph.png"><img src="files/images/graph.png" border =0 width=300 style="padding-left:10px; float:right;"></a></p>
<p>Big data and security intelligence are the two very hot topics in security. We are collecting more and more information from both the infrastructure, but increasingly also directly from our applications. This vast amount of data gets increasingly hard to understand. Terms like map reduce, hadoop, spark, elasticsearch, data science, etc. are part of many discussions. But what are those technologies and techniques? And what do they have to do with security analytics/intelligence? We will see that none of these technologies are sufficient in our quest to defend our networks and information. <B><I>Data visualization</i></b> is the only approach that scales to the ever changing threat landscape and infrastructure configurations. Using big data visualization techniques, you uncover hidden patterns of data, identify emerging vulnerabilities and attacks, and respond decisively with countermeasures that are far more likely to succeed than conventional methods. Something that is increasingly referred to as <b><i>hunting</i></b>. The attendees will learn about log analysis, big data, information visualization, data sources for IT security, and learn how to generate visual representations of IT data. The training is filled with hands-on exercises utilizing the <a href="http://davix.secviz.org">DAVIX</a> live CD.</p>
<p><br/><br />
<H3>What's New?</H3></p>
<p>The workshop is being heavily updated over the next months. Check back here to see a list of new topics:</p>
<ul>
<li>Security Analytics - UEBA, Scoring, Anomaly Detection</li>
<li>Hunting</li>
<li>Data Science</li>
<li>10 Challenges with SIEM and Big Data for Security</li>
<li>Big Data - How do you navigate the ever growing landscape of Hadoop and big data technologies? Tajo, Apache Arrow, Apache Drill, Druid, PrestoDB from Facebook, Kudu, etc. We'll sort you out.</li>
</ul>
<p><br/></p>
<h3>SYLLABUS</h3>
<p><a href="files/images/Screen&#32;Shot&#32;2014-10-31&#32;at&#32;12.13.15&#32;PM.preview.png"><img src="files/images/Screen&#32;Shot&#32;2014-10-31&#32;at&#32;12.13.15&#32;PM.preview.png" width=300 style="float:right;"></a></p>
<p>The syllabus is not 100% fixed yet. Stay tuned for some updates.</p>
<p><b><i>Day 1:</i></b></p>
<p><b>Log Analysis</b></p>
<ul>
<li>Data Sources Discussion - including PCAP, Firewall, IDS, Threat Intelligence (TI) Feeds, CloudTrail, CloudWatch, etc.</li>
<li>Data Analysis and Visualization Linux (DAVIX)</li>
<li>Log Data Processing (CSVKit, ...)</li>
</ul>
<p><b>SIEM, and Big Data</b></p>
<ul>
<li>Log Management and SIEM Overview</li>
<li>LogStash (Elastic Stack) and Moloch</li>
<li>Big Data - Hadoop, Spark, ElasticSearch, Hive, Impala</li>
</ul>
<p><b>Data Science</b></p>
<ul>
<li>Introduction to Data Science</li>
<li>Introduction to Data Science with R</li>
<li><b>Hunting</b></li>
</ul>
<p><b><i>Day 2:</i></b></p>
<p><b>Visualization</b><br />
<img src="files/images/pixl_link.png" border =0 width=450 style="padding-left:10px; float:right;"></p>
<ul>
<li>Information Visualization History</li>
<li>Visualization Theory</li>
<li>Data Visualization Tools and Libraries (e.g., Mondrian, Gephi, AfterGlow, Graphiti)</li>
<li>Visualization Resources</li>
</ul>
<p><b>Security Visualization Use-Cases</b></p>
<ul>
<li>Perimeter Threat</li>
<li>Network Flow Analysis</li>
<li>Firewall Visualization</li>
<li>IDS/IPS Signature Analysis</li>
<li>Vulnerability Scans</li>
<li>Proxy Data</li>
<li>User Activity</li>
<li>Host-based Data Analysis</li>
</ul>
<p></br><br />
<a href="files/images/newer_small.png"><img src="files/images/newer_small.png" border =0 width=300 style="padding-left:10px; float:right;"></a></p>
<h3>Sample of Tools and Techniques</h3>
<p>Tools to <b>gather data</b>:</p>
<ul>
<li>argus, nfdump, nfsen, and silk to process traffic flows</li>
<li>snort, bro, suricata as intrusion detection systems</li>
<li>p0f, npad for passive network analysis</li>
<li>iptables, pf, pix as examples of firewalls</li>
<li>OSSEC, collectd, graphite for host data</li>
</ul>
<p>We are also using a number of <b>visualization tools</b> to analyze example data in the labs:</p>
<ul>
<li>graphviz, tulip, cytoscape, and gephi</li>
<li>afterglow</li>
<li>treemap</li>
<li>mondrian, ggobi</li>
</ul>
<p>Under the <b>log management</b> section, we are going to discuss:</p>
<ul>
<li>rsyslog, syslog-ng, nxlog</li>
<li>logstash as part of the elastic stack, moloch</li>
<li>commercial log management and SIEM solutions</li>
</ul>
<p>The section on <b>big data</b> is covering the following:<br />
<img src="files/images/pixl_dash_avail.png" border =0 width=450 style="padding-left:10px; float:right;"></p>
<ul>
<li>hadoop (HDFS, map-reduce, HBase, Hive, Impala, Zookeper)</li>
<li>search engines like: elastic search, Solr</li>
<li>key-value stores like MongoDB, Cassandra, etc.</li>
<li>OLAP and OLTP</li>
<li>The Spark ecosystem</li>
</ul>
<p><br></p>
<p><font size=+2><center><a href="http://ubm.io/2khLkKR">SIGN UP</a></center></font></p>
<h3>TRAINER</h3>
<p><a href="http://raffy.ch">Raffael Marty</a> is vice president of security analytics at Sophos, and is responsible for all strategic efforts around security analytics for the company and its products. He is based in San Francisco, Calif. Marty is one of the world's most recognized authorities on security data analytics, big data and visualization. His team at Sophos spans these domains to help build products that provide Internet security solutions to Sophos' vast global customer base.</p>
<p>Previously, Marty launched pixlcloud, a visual analytics platform, and Loggly, a cloud-based log management solution. With a track record at companies including IBM Research, ArcSight, and Splunk, he is thoroughly familiar with established practices and emerging trends in the big data and security analytics space. Marty is the author of Applied Security Visualization and a frequent speaker at academic and industry events. Zen meditation has become an important part of Raffy's life, sometimes leading to insights not in data but in life.</p>
  </div>
  
    
</div>
<div class="node" id="node-1146">
      <h2 class="title">
      <a href="content/secuirty-visualization-case-study.html">Secuirty Visualization Case Study</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted December 22nd, 2016 by doug.cogswell@a...</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_3"><a href="news.html" rel="tag" title="This is where you can start discussions around security visualization topics. Add your own entry and have people make comments." class="taxonomy_term_3">Discussion Entries</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <p>We recently posted a case study of how a Fortune 100 company is using Security Visualization as a front end to their various data collection systems.  The Security Visualization allows the company's analysts to look at 100's of thousands of correlations each day and apply human pattern recognition to spot the "needles in the haystack".  These are threats that are designed to avoid traditional intrusion and event management.  Once the potential threat is identified and the log data is carved down to just the logs that are relevant, that subset of log data is then attached to a case study and delivered to case investigation for further evaluation.  In addition to identifying and carving down to just the relevant logs, the security visualization also makes it easier to communicate the findings to the extended team.</p>
<p>In this situation data is imported from several sources.  Those sources include intrusion detection systems (e.g., SourceFire), firewall protection (e.g., Palo Alto, SonicWALL), and virus scan / endpoint protection (e.g. Symantec) in addition to correlation systems (e.g., HP ESM, Splunk, etc.).  Security Visualization allows the analysts to hunt for unknown and unexpected threats. Threats such as time staged attacks, diagonal attacks, cluster attacks, octal jump attacks, embedded activity attacks, etc.   </p>
<p>This case study is recorded and can be viewed at http://www.advizorsolutions.com/articles/security-visualization.  The case study lasts 25 minutes, and is followed by a Q&amp;A.</p>
<p>Doug Cogswell,<br />
ADVIZOR Solutions, Inc.</p>
  </div>
  
    
</div>
<div class="node" id="node-1145">
      <h2 class="title">
      <a href="content/security-visualization-requirements-phd-thesis-survey.html">Security Visualization Requirements- Phd Thesis Survey</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted November 17th, 2016 by ferda.ozdemir@m...</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_3"><a href="news.html" rel="tag" title="This is where you can start discussions around security visualization topics. Add your own entry and have people make comments." class="taxonomy_term_3">Discussion Entries</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <p>Hi, I am a Phd candidate in Informatics Institude at Middle East Technical University. I prepared an online survey as a part of my phd thesis. However, since this subject is relatively new I can not find anybody who may fill this survey around me in Turkey. </p>
<p>The survey is in Google Forms, at link https://goo.gl/forms/xbfmrqJ4jxA4rvQ53. It is not very short :( It may take around 20 minutes but it is easy to fill, mostly composed of multi selection questions. Uncompleted survey results are not saved so the participants should complete the survey. </p>
<p>Although we ask questions related to security systems and security visualization systems used to understand the visualization requirements.The survey, in general, does not include questions that give personal discomfort. No tracking information such as email or organization name is asked during the survey. More descriptive information about how the survey results will be used exists in the starting page. So, please do not hesitate to fill, due to your privacy concerns.</p>
<p>I hope experts of this forum may help me by filling the survey during a coffee break. I need to take feedback soon, before my next thesis committee. I appreciate your help to a newbie security visualization researcher (me) :) </p>
<p>Many thanks,<br />
Ferda Özdemir Sönmez</p>
  </div>
  
    
</div>
<div class="node" id="node-1144">
      <h2 class="title">
      <a href="content/vizsec-2016-call-papers.html">VizSec 2016 Call for Papers</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted July 12th, 2016 by neeko</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_3"><a href="news.html" rel="tag" title="This is where you can start discussions around security visualization topics. Add your own entry and have people make comments." class="taxonomy_term_3">Discussion Entries</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <p>The 13th IEEE Symposium on Visualization for Cyber Security (VizSec) is a forum that brings together researchers and practitioners from academia, government, and industry to address the needs of the cybersecurity community through new and insightful visualization and analysis techniques. VizSec provides an excellent venue for fostering greater exchange and new collaborations on a broad range of security- and privacy-related topics. VizSec will be held in Baltimore, MD, USA in conjunction with IEEE VIS.</p>
<p>The purpose of VizSec is to explore effective and scalable visual interfaces for security domains such as network security, computer forensics, reverse engineering, insider threat detection, cryptography, privacy, user assisted attacks prevention, compliance management, wireless security, secure coding, and penetration testing.</p>
<p><strong>Technical Papers</strong></p>
<p>Full papers describing novel contributions in security visualization are solicited. Papers may present techniques, applications, practical experience, theory, analysis, experiments, or evaluations. We encourage the submission of papers on technologies and methods that promise to improve cyber security practices, including, but not limited to:</p>
<p> - Situation awareness and/or understanding<br />
 - Incident handling including triage, exploration, correlation, and response<br />
 - Computer forensics<br />
 - Recording and reporting results of investigations<br />
 - Assisting proactive security configuration and deployment<br />
 - Reverse engineering and malware analysis<br />
 - Vulnerability management<br />
 - Multiple data source analysis<br />
 - Analyzing information requirements for computer network defense<br />
 - Evaluation and/or user testing of VizSec systems<br />
 - Criteria for assessing the effectiveness of cyber security visualizations<br />
   (whether from a security goal perspective or a human factors perspective)<br />
 - Modeling system and network behavior<br />
 - Modeling attacker and defender behavior<br />
 - Studying risk and impact of cyber attacks<br />
 - Predicting future attacks or targets<br />
 - Security metrics and education<br />
 - Software security<br />
 - Mobile application security<br />
 - Social networking privacy and security</p>
<p>When applicable, visualization and interaction techniques that effectively capture the insights of human analysts and/or allow analysts to collaborate efficiently are particularly desirable.</p>
<p><strong>*** New for 2016! *** Case Studies</strong></p>
<p>Short papers describing practical applications of security visualization are solicited. We encourage the submission of papers discussing the introduction of cyber security visualizations into operational context, including, but not limited to:</p>
<p> - Cases where visualization made positive contributions towards meeting<br />
   operational needs<br />
 - Gaps or negative outcomes from visualization deployments<br />
 - Situations where visualization was not utilized, but could have had a<br />
   positive impact<br />
 - Lessons learned from operational engagements<br />
 - Insights gained from the transition process</p>
<p>Cyber security practitioners from industry, as well as the research community, are encouraged to submit case studies.</p>
<p><strong>Posters</strong></p>
<p>Poster submissions may showcase late-breaking results, work in progress, preliminary results, or visual representations relevant to the VizSec community. The poster program will be a great opportunity for the authors to interact with the attendees and solicit feedback.</p>
<p><strong>Submissions</strong></p>
<p>Submissions must be formated using the IEEE VGTC template that can be found at http://junctionpublishing.org/vgtc/Tasks/camera.html. All submissions should be in PDF format.</p>
<p>Submit papers and poster abstracts using EasyChair: http://www.easychair.org/conferences/?conf=vizsec2016</p>
<p>Papers should be at most 8 pages including the bibliography and appendices. Papers will be peer-reviewed by at least 3 members of the program committee. Committee members are not required to read the appendices or any pages past the maximum. Submissions not meeting these guidelines will be rejected without consideration of their merit. Reviews are single-blind, so authors may include names and affiliations in their submissions. Submitted papers must not substantially overlap papers that have been published or that are simultaneously submitted to a journal or a conference with proceedings.</p>
<p>The VizSec proceedings will be published by IEEE. Authors of accepted papers must guarantee that their papers will be presented at the conference.<br />
Case Studies</p>
<p>Case studies should be at most 4 pages including the bibliography and appendices. Case study submissions will be reviewed by the Paper Chair(s) and other members of the organizing committee to determine relevance to the VizSec community.</p>
<p>Accepted case study authors will have time to present their work at VizSec during the program.</p>
<p>Accepted case studies will be made available on this website.</p>
<p>Extended abstract for posters should be at most 2 pages including the bibliography. Poster abstracts will be reviewed by the Poster Chair(s) and other members of the organizing committee to determine relevance to the VizSec community.</p>
<p>Accepted authors must present a corresponding poster during the workshop. The poster authors can determine the layout by themselves, but the dimensions of the posters should not exceed the A0 space (841mm x 1189mm or 33.1" x 46.8"). Additionally, poster authors are requested to give a brief oral preview during a plenary "fast forward" session.</p>
<p>Accepted poster abstracts will be made available on <a href="http://vizsec.org/">VizSec website</a>.</p>
<p>When applicable, submissions including tests and evaluations of the proposed tools and techniques are considered particularly desirable. If possible, making the data used for the tests available will also be considered positively. If you do not have real-world data to demonstrate your visualization, you may be interested in looking at the VAST Challenge data sets.</p>
<p><strong>Important Dates</strong></p>
<p>All deadlines are 5:00 PM PST</p>
<p>Papers and Case Studies</p>
<p>  August 1, 2016<br />
    Submission for Papers and Case Studies<br />
  September 5, 2016<br />
    Author Notification for Papers and Case Studies<br />
  October 3, 2016<br />
    Camera Ready Submission and Copyright Forms for Papers</p>
<p>Posters</p>
<p>  September 19, 2016<br />
    Abstract Submission for Posters<br />
  September 30, 2016<br />
    Author Notification for Posters</p>
  </div>
  
    
</div>
<div class="node" id="node-1141">
      <h2 class="title">
      <a href="content/visualizing-live-streams-3dvr.html">Visualizing Live Streams in 3D/VR</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted February 15th, 2016 by arkowitz</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_3"><a href="news.html" rel="tag" title="This is where you can start discussions around security visualization topics. Add your own entry and have people make comments." class="taxonomy_term_3">Discussion Entries</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <p>We've created a free tool for visualizing live streams of network traffic, using JMonkeyEngine (Java 3D gaming engine).</p>
<p>Please take a look at <a href="http://deepnode.com">deepnode.com</a> - we would very much appreciate feedback from this community.</p>
<p>Rather than focusing on mining of static datasets, this tool focuses on seeing activity over time, and controlling the timeline so that a human can connect the dots. Here's a link to information on the <a href="http://www.deepnode.com/the-concept/">concept</a> behind the visualization style.</p>
<p>As for the screenshot, this <a href="https://www.youtube.com/watch?v=Stb-eeaLQRs">video</a>  explains what you're looking at.</p>
  </div>
  
    
</div>
<div class="node" id="node-1142">
      <h2 class="title">
      <a href="content/screenshot-ip-traffic-deep-node.html">screenshot of ip traffic in deep node</a>
    </h2>
  
    
  
    <div class="meta">
  
          <div class="submitted">Posted February 15th, 2016 by arkowitz</div> 
        
        
  </div>
    
  <div class="content">
    <a href="content/screenshot-ip-traffic-deep-node.html"><img src="files/images/dnshot_bright.thumbnail.png" alt="screenshot of ip traffic in deep node" title="screenshot of ip traffic in deep node"  class="image image-thumbnail " width="150" height="97" /></a>  </div>
  
    
</div>
<div class="node" id="node-1136">
      <h2 class="title">
      <a href="content/youtube-video-using-afterglow-twopi-and-nginx-logs.html">Youtube video using Afterglow, twopi and Nginx logs.</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted March 30th, 2015 by jdellinger</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_3"><a href="news.html" rel="tag" title="This is where you can start discussions around security visualization topics. Add your own entry and have people make comments." class="taxonomy_term_3">Discussion Entries</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <p>I attended <a href="http://secviz.org/content/visual-analytics-workshop-blackhat-2015">Visual Analytics Workshop</a> last year at BlackHat and have gotten endless use from <a href="http://afterglow.sf.net">afterglow</a>, neato, etc to make interesting visualizations.</p>
<p>Here is a short youtube video I put together, with attack data taken from Nginx logs:  </p>
<p><center><br />
<iframe width="560" height="315" src="https://www.youtube.com/embed/gFRHdyy6Rnc" frameborder="0" allowfullscreen></iframe><br />
</center></p>
<p>(Music is by a local San Francisco band: Vetiver)</p>
  </div>
  
    
</div>
<div class="node" id="node-1135">
      <h2 class="title">
      <a href="content/dns-mapping.html">DNS Mapping</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted March 28th, 2015 by hackertarget</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_5"><a href="category/image-galleries/just-images.html" rel="tag" title="These images are for article posts. They are not shown in the image gallery" class="taxonomy_term_5">Just Images</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <a href="content/dns-mapping.html"><img src="files/images/secviz.org.thumbnail.png" alt="DNS Mapping" title="DNS Mapping"  class="image image-thumbnail " width="150" height="31" /></a><p>Over at <a href="http://dnsdumpster.com/">dnsdumpster.com</a> I created a DNS recon tool that generates a DNS map on the fly using 80+GB of DNS data from the <a href="https://scans.io">scans.io</a> project. This map is the secviz.org domain.</p>
  </div>
  
    
</div>
<div class="node" id="node-1134">
      <h2 class="title">
      <a href="content/mydoom-botnet.html">MyDoom botnet</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted March 26th, 2015 by dej611</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_1"><a href="category/image-galleries/graph-exchange.html" rel="tag" title="This is the place where you can share your graphs." class="taxonomy_term_1">Graph Exchange</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <a href="content/mydoom-botnet.html"><img src="files/images/Screen&#32;Shot&#32;2014-03-28&#32;at&#32;12.33.29.thumbnail.png" alt="MyDoom botnet" title="MyDoom botnet"  class="image image-thumbnail " width="150" height="77" /></a><p>This graph visualization shows the propagation of malware through a deliberately infected computer network. Twelve machines in the network were infected to see how the traffic spread to other machines. Over 7800 machines were included in the dataset.<br />
All network in a single chart. Yellow links indicate benign traffic; red links indicate traffic with at least 1 infected packet. Nodes are sized by volume of traffic.<br />
Data taken from the MyDoom-A.tar.gz, available <a href="http://wisnet.seecs.nust.edu.pk/projects/ENS/DataSets.html">here</a><br />
Image generated with KeyLines.</p>
  </div>
  
    
</div>
<div class="node" id="node-1133">
      <h2 class="title">
      <a href="content/botnet-activity.html">Botnet activity</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted March 26th, 2015 by dej611</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_1"><a href="category/image-galleries/graph-exchange.html" rel="tag" title="This is the place where you can share your graphs." class="taxonomy_term_1">Graph Exchange</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <a href="content/botnet-activity.html"><img src="files/images/Screen&#32;Shot&#32;2015-03-26&#32;at&#32;12.13.57.thumbnail.png" alt="Botnet activity" title="Botnet activity"  class="image image-thumbnail " width="150" height="141" /></a><p>Visualization showing botnet activity geographically. The time bar at the bottom shows temporal trends and filters traffic shown on the map.<br />
Data from http://www.caida.org/data/passive/sipscan_dataset.xml.<br />
Image generated using KeyLines.</p>
  </div>
  
    
</div>
<div class="node" id="node-1132">
      <h2 class="title">
      <a href="content/botnet-traffic.html">Botnet traffic</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted March 26th, 2015 by dej611</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_1"><a href="category/image-galleries/graph-exchange.html" rel="tag" title="This is the place where you can share your graphs." class="taxonomy_term_1">Graph Exchange</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <a href="content/botnet-traffic.html"><img src="files/images/KeyLines&#32;(21).thumbnail.png" alt="Botnet traffic" title="Botnet traffic"  class="image image-thumbnail " width="150" height="106" /></a><p>Using a dataset from http://www.uvic.ca/engineering/ece/isot/datasets/index.php, this graph shows botnet traffic between 5000 computers at the University of San Diego. Different colors were used to indicate different protocols. Nodes represent computers and were sized by degree. Edges represent packets, weighted by packet size. Image generated using KeyLines.</p>
  </div>
  
    
</div>
<div class="node" id="node-1129">
      <h2 class="title">
      <a href="content/visual-analytics-needs-a-strong-data-backend.html">Visual Analytics Needs a Strong Data Backend</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted March 10th, 2015 by raffy</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_3"><a href="news.html" rel="tag" title="This is where you can start discussions around security visualization topics. Add your own entry and have people make comments." class="taxonomy_term_3">Discussion Entries</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <p>Visual Analytics, especially the <B><i>exploration</i></b> of data requires a scalable and flexible data backend. It is not uncommon that gigabytes, maybe even terabytes of data need to be queried for a specific analytics tasks. Furthermore, the more <i><b>context</i></b> around log data is available, the more expressive the data gets and the deeper the insight that can be discovered in the data. How can we gather all that context and combine it with both network-based, as well as host-based data? What are the data access requirements? How can we run data mining algorithms, such as clustering across all of the data? What kind of data store do we need for that? Do we need a search engine as a backend? Or a columnar data store?</p>
<p>I recently wrote a paper about the topic of a <b><i><a href="http://bit.ly/1FN1W5e">security data lake</a></i></b> that is a concept of a data backend enabling a variety of processing and access use-cases. A short <a href="http://bit.ly/1A07Axm">introduction</a> to the topic is available as well.</p>
<p>Maybe at a later point in time, I will try to address the topic of data science and techniques, as well as workflows to make all that big data actionable. How do you take a terabyte of data and find actual insights? Just dropping that data into a network graph visualization is not going to help. You need a bit more to make that happen. But again, more on that later.</p>
<p>If you want to learn more about how to visualize and analyze terabytes of data, attend the <b><a href="http://secviz.org/content/visual-analytics-workshop-blackhat-2015"> Visual Analytics Workshop</a></b> at BlackHat 2015 in Las Vegas.</p>
<p>Again, here is where you <a href="http://bit.ly/1FN1W5e">download</a> the paper.</p>
  </div>
  
    
</div>
<div class="node" id="node-1128">
      <h2 class="title">
      <a href="content/linked-graphs-showing-dns-traffic-network.html">Linked Graphs Showing DNS Traffic on the Network</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted February 23rd, 2015 by raffy</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_1"><a href="category/image-galleries/graph-exchange.html" rel="tag" title="This is the place where you can share your graphs." class="taxonomy_term_1">Graph Exchange</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <a href="content/linked-graphs-showing-dns-traffic-network.html"><img src="files/images/Screen&#32;Shot&#32;2014-10-31&#32;at&#32;12.13.15&#32;PM.thumbnail.png" alt="Linked Graphs Showing DNS Traffic on the Network" title="Linked Graphs Showing DNS Traffic on the Network"  class="image image-thumbnail " width="150" height="91" /></a><p>This is a screenshot from a tool called Mondrian where we show network traffic. DNS traffic in particular. The bar charts show the breakdown of sources, destinations, and ports. The parallel coordinate shows all three variables at the same time. The red parts highlight an interesting visual pattern. What is it?</p>
  </div>
  
    
</div>
<div class="node" id="node-1125">
      <h2 class="title">
      <a href="content/my-laptop-communicating.html">My Laptop Communicating</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted February 6th, 2015 by raffy</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_1"><a href="category/image-galleries/graph-exchange.html" rel="tag" title="This is the place where you can share your graphs." class="taxonomy_term_1">Graph Exchange</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <a href="content/my-laptop-communicating.html"><img src="files/images/newer_small.thumbnail.png" alt="My Laptop Communicating" title="My Laptop Communicating"  class="image image-thumbnail " width="142" height="150" /></a><p>This link graph shows communications of my laptop. The big cluster in the middle is Web traffic. The surroundings are all kinds of processes running under OSX. The output was rendered in WebGL. Copyright 2015 pixlcloud llc.</p>
  </div>
  
    
</div>
<div class="node" id="node-1124">
      <h2 class="title">
      <a href="content/network-flows-linked-views.html">Network Flows - Linked Views</a>
    </h2>
  
    
  
    <div class="meta with-taxonomy">
  
          <div class="submitted">Posted February 6th, 2015 by raffy</div> 
        
     
      <div class="taxonomy"><ul class="links inline"><li class="first last taxonomy_term_1"><a href="category/image-galleries/graph-exchange.html" rel="tag" title="This is the place where you can share your graphs." class="taxonomy_term_1">Graph Exchange</a></li>
</ul></div>
        
  </div>
    
  <div class="content">
    <a href="content/network-flows-linked-views.html"><img src="files/images/Screen&#32;Shot&#32;2014-09-24&#32;at&#32;11.28.57&#32;AM.thumbnail.png" alt="Network Flows - Linked Views" title="Network Flows - Linked Views"  class="image image-thumbnail " width="150" height="91" /></a><p>This image shows a network flow graph of flow events. The output is rendered in WebGL through a proprietary tool. Copyright 2015 pixlcloud llc</p>
  </div>
  
    
</div>
<div class="pager"><span class="pager-list"><strong class="pager-current">1</strong><a href="node%3Fpage=1.html" class="pager-next active" title="Go to page 2">2</a><a href="node%3Fpage=2.html" class="pager-next active" title="Go to page 3">3</a><a href="node%3Fpage=3.html" class="pager-next active" title="Go to page 4">4</a><a href="node%3Fpage=4.html" class="pager-next active" title="Go to page 5">5</a><a href="node%3Fpage=5.html" class="pager-next active" title="Go to page 6">6</a><a href="node%3Fpage=6.html" class="pager-next active" title="Go to page 7">7</a><a href="node%3Fpage=7.html" class="pager-next active" title="Go to page 8">8</a><a href="node%3Fpage=8.html" class="pager-next active" title="Go to page 9">9</a><span class="pager-ellipsis">…</span></span><a href="node%3Fpage=1.html" class="pager-next active" title="Go to next page">next ›</a><a href="node%3Fpage=15.html" class="pager-last active" title="Go to last page">last »</a></div>              </div>
      </div>
      
        

      
    </div>

    <div id="footer">
      © 2008-2015, Raffael Marty @ <A>PixlCloud</a>
    </div>

    
    <script type="text/javascript" src="modules/google_analytics/googleanalytics.js"></script>
<script type="text/javascript">var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script>
<script type="text/javascript">var pageTracker = _gat._getTracker("UA-20630881-5");pageTracker._trackPageview();</script>
    
  </div>

</body>
</html>
