NStreamAware: Real-Time Visual Analytics for Data Streams to Enhance Situational Awareness

Similar documents
Visual Support for Analyzing Network Traffic and Intrusion Detection Events using TreeMap and Graph Representations

Finding Anomalies in Time- Series using Visual Correla/on for Interac/ve Root Cause Analysis

Flexible Web Visualization for Alert-Based Network Security Analytics

BIG DATA FOR MEDIA SIGMA DATA SCIENCE GROUP MARCH 2ND, OSLO

Network Metrics Content Pack for VMware vrealize Log Insight

Big Data Web Analytics Platform on AWS for Yottaa

Innovative, High-Density, Massively Scalable Packet Capture and Cyber Analytics Cluster for Enterprise Customers

Information Visualization and Visual Analytics

An example. Visualization? An example. Scientific Visualization. This talk. Information Visualization & Visual Analytics. 30 items, 30 x 3 values

Elasticsearch on Cisco Unified Computing System: Optimizing your UCS infrastructure for Elasticsearch s analytics software stack

Reference Architecture, Requirements, Gaps, Roles

Challenge 10 - Attack Visualization The Honeynet Project / Forensic Challenge 2011 /

YOU VS THE SENSORS. Six Requirements for Visualizing the Internet of Things. Dan Potter Chief Marketing Officer, Datawatch Corporation

Big Data Analytics - Accelerated. stream-horizon.com

SQL + NOSQL + NEWSQL + REALTIME FOR INVESTMENT BANKS

Databricks. A Primer

PALANTIR CYBER An End-to-End Cyber Intelligence Platform for Analysis & Knowledge Management

A New Approach to Network Visibility at UBC. Presented by the Network Management Centre and Wireless Infrastructure Teams

An Introduction to SAS Enterprise Miner and SAS Forecast Server. André de Waal, Ph.D. Analytical Consultant

Big Data Technology ดร.ช ชาต หฤไชยะศ กด. Choochart Haruechaiyasak, Ph.D.

Hurwitz ValuePoint: Predixion

Databricks. A Primer

Big Data and Analytics (Fall 2015)

How In-Memory Data Grids Can Analyze Fast-Changing Data in Real Time

SIMPLE MACHINE HEURISTIC INTELLIGENT AGENT FRAMEWORK

Big Data Visualization and Dashboards

BIG DATA ANALYTICS For REAL TIME SYSTEM

What s New in Security Analytics Be the Hunter.. Not the Hunted

GigaSpaces Real-Time Analytics for Big Data

Information Retrieval Elasticsearch

STREAM ANALYTIX. Industry s only Multi-Engine Streaming Analytics Platform

NEEDLE STACKS & BIG DATA: USING EVENT STREAM PROCESSING FOR RISK, SURVEILLANCE & SECURITY ANALYTICS IN CAPITAL MARKETS

Production Optimization through Advanced Condition Monitoring of Upstream Oil and Gas Assets

XpoLog Competitive Comparison Sheet

TORNADO Solution for Telecom Vertical

How To Understand The Benefits Of Big Data

Predictive Analytics

White Paper. How Streaming Data Analytics Enables Real-Time Decisions

Information Visualization WS 2013/14 11 Visual Analytics

How To Create A Graph On An African Performance Monitor (Dvt)

The Next Big Thing in the Internet of Things: Real-Time Big Data Analytics"

SGT Technology Innovation Center Dasvis Project

Big Data & QlikView. Democratizing Big Data Analytics. David Freriks Principal Solution Architect

Big Data a threat or a chance?

6 Steps to Faster Data Blending Using Your Data Warehouse

Situational Awareness Through Network Visualization

COULD VS. SHOULD: BALANCING BIG DATA AND ANALYTICS TECHNOLOGY WITH PRACTICAL OUTCOMES

Ad Hoc Analysis of Big Data Visualization

ElegantJ BI. White Paper. Operational Business Intelligence (BI)

Essential Elements of an IoT Core Platform

BIG Data Analytics Move to Competitive Advantage

Embedded Analytics & Big Data Visualization in Any App

Highly Scalable Tile-Based Visualization for Exploratory Data Analysis

Three Open Blueprints For Big Data Success

Integrating a Big Data Platform into Government:

REAL-TIME STREAMING ANALYTICS DATA IN, ACTION OUT

Lambda Architecture. Near Real-Time Big Data Analytics Using Hadoop. January Website:

How To Turn Big Data Into An Insight

Simplifying Big Data Analytics: Unifying Batch and Stream Processing. John Fanelli,! VP Product! In-Memory Compute Summit! June 30, 2015!!

Welcome to the second half ofour orientation on Spotfire Administration.

Deploy. Friction-free self-service BI solutions for everyone Scalable analytics on a modern architecture

Complex, true real-time analytics on massive, changing datasets.

SOLUTION BRIEF. Increase Business Agility with the Right Information, When and Where It s Needed. SAP BusinessObjects Business Intelligence Platform

Towards Smart and Intelligent SDN Controller

How to Use Boards for Competitive Intelligence

BI & ANALYTICS FOR NAV & AX

Case Study: Real-time Analytics With Druid. Salil Kalia, Tech Lead, TO THE NEW Digital

Analance Data Integration Technical Whitepaper

Cisco Integrated Video Surveillance Solution: Expand the Capabilities and Value of Physical Security Investments

The Purview Solution Integration With Splunk

Dynamic Visual Analytics Facing the Real-Time Challenge

Real-time Data Analytics mit Elasticsearch. Bernhard Pflugfelder inovex GmbH

Cloudera Enterprise Data Hub in Telecom:

Getting Started with Analytics and Reports Oracle Financials Cloud

Big Data for Satellite Business Intelligence

Beyond Watson: The Business Implications of Big Data

Insurance Business Intelligence Solution

XpoLog Center Suite Data Sheet

Information Technology Policy

SAP Business One and SAP HANA

Data Governance in the Hadoop Data Lake. Kiran Kamreddy May 2015

Using Big Data Analytics for Financial Services Regulatory Compliance

Analance Data Integration Technical Whitepaper

Lambda Architecture for Batch and Real- Time Processing on AWS with Spark Streaming and Spark SQL. May 2015

TURN YOUR DATA INTO KNOWLEDGE

Synerscope Sept 2013

White Paper: Leveraging Web Intelligence to Enhance Cyber Security

A very short talk about Apache Kylin Business Intelligence meets Big Data. Fabian Wilckens EMEA Solutions Architect

Transcription:

Symposium on Visualization for Cyber Security (VizSec 2014) 10th November 2014, Paris, France NStreamAware: Real-Time Visual Analytics for Data Streams to Enhance Situational Awareness Fabian Fischer and Daniel A. Keim Fabian Fischer Data Analysis and Visualization Group University of Konstanz

Motivation: Heterogeneous Data Streams Network Alerts (e.g., OSSEC) Syslog Messages NetFlow Data Analyzing Data Streams = Crucial for security in your network! REAL-TIME VISUAL ANALYTICS Monitoring & Exploration Crucial for situational awareness (SA)! Fabian Fischer NStreamAware: Real-Time Visual Analytics for Data Streams to Enhance Situational Awareness 2

DATA CHALLENGE How to make stream analysis scalable?

Data Streams (from various sources) Web Application (NVisAware) NStreamAware: Scalable Infrastructure REST Service (VACS-REST) REST Distributed Streaming Analytics SPARK Service (VACS-Spark) MongoDB ElasticSearch Apache Spark is a fast and general engine for large-scale data processing which can run on a distributed computer cluster. Fabian Fischer NStreamAware: Real-Time Visual Analytics for Data Streams to Enhance Situational Awareness 4

Integrated Perspectives Real-Time Data Stream Monitoring Real-Time Sliding Slices (NVisAware) Visual Feature Selection Summarized Sliding Slices Event Timeline & Insights Search & Exploration Fabian Fischer NStreamAware: Real-Time Visual Analytics for Data Streams to Enhance Situational Awareness 5

Real-Time Data Stream Monitoring Fabian Fischer NStreamAware: Real-Time Visual Analytics for Data Streams to Enhance Situational Awareness 6

Demo

SITUATIONAL AWARENESS CHALLENGE How to reduce the cognitive load?

Data Streams (from various sources) Web Application (NVisAware) NVisAware: Analytics REST Service (VACS-REST) REST Visual Analytics Approach: Calculate and visualize sliding slices. (based on sliding windows) Distributed Streaming Analytics SPARK Service (VACS-Spark) MongoDB ElasticSearch Calculate Sliding Slice Summary for each sliding window. Push slice t to web application. Fabian Fischer NStreamAware: Real-Time Visual Analytics for Data Streams to Enhance Situational Awareness 10

Real-Time Sliding Slice slice t Interactive Widgets Treemaps Counters Node-link diagrams Interactions Star/Annotate slice Remove slice Retrieve data Color Encoding Background for similarity Importance of alerts Fabian Fischer NStreamAware: Real-Time Visual Analytics for Data Streams to Enhance Situational Awareness 11

Demo

EXPLORATION CHALLENGE How to explore many sliding slices?

Visual Feature Selection Visual Analytics Approach: Aggregate / Summarize according interest function (visually steered by the expert) Fabian Fischer NStreamAware: Real-Time Visual Analytics for Data Streams to Enhance Situational Awareness 18

Example: Using Visual Analytics for Interactive Summarization Fabian Fischer NStreamAware: Real-Time Visual Analytics for Data Streams to Enhance Situational Awareness 19

Demo

Application to Real-Time Social Media Analysis (VAST Challenge 2014 MC3) Real-Time Monitoring Task: Discover major events in the stream to support an ongoing police operation. Available Data Stream: Real-time feeds of microblogs and emergency calls. Successful participation: Award for Outstanding Comprehensive Mini-Challenge 3 Submission Fabian Fischer NStreamAware: Real-Time Visual Analytics for Data Streams to Enhance Situational Awareness 22

Further Challenges and Future Work Challenge: Parameter adjustment for sliding slices and clustering. Automated merging of sliding slices based on the interest function. Performance Evaluation for a large network using security operational data stream. Responsiveness issues when increasing the number of complex interactive visualizations. Data retention and rotation for the visualization interface. Fabian Fischer NStreamAware: Real-Time Visual Analytics for Data Streams to Enhance Situational Awareness 23

Contributions DATA CHALLENGE How to make stream analysis scalable? SA CHALLENGE How to reduce the cognitive load? EXPLORATION CHALLENGE How to explore many sliding slices? NStreamAware Building a web-based visual analytics system using scalable technologies. NVisAware Sliding Slices Visualization with embedded visualization widgets. NVisAware Summarized Sliding Slices steered using interactive visualizations. Fabian Fischer NStreamAware: Real-Time Visual Analytics for Data Streams to Enhance Situational Awareness 24

Thank you very much for your attention! Questions? For more information about this work please contact Fabian Fischer Tel. +49 7531 88-2780 Fabian.Fischer@uni-konstanz.de @f2cx http://ff.cx/ Fabian Fischer NStreamAware: Real-Time Visual Analytics for Data Streams to Enhance Situational Awareness 25