25 Step SecVis Creation Process
25 Step SecVis Creation Process
• Identify trends
• Discover relationships
• Discover patterns
• Understand data
• Summarize data
• Support decisions
• Triage Analysis
• Escalation Analysis
• Correlation Analysis
• Threat Analysis
• Attack Forecasting
• Forensic Analysis
• 2D or 3-D ?
• Install all necessary software (sensor, collector, library, visualization tool, IDE)
• Clean
• Alert types
• Event type
• Time
• Duration
• Error type
• Asset id
• Departmental division
• Geo Info(Coordinates)
• Aggregation (Summary)
1) Count
2) Size
1) Count
2) Size
3) Set
1) Group of users
3) Group of applications
• Ratio (Understand)
7) Overlapping (Comparison)
8) Statistical calculations
• Title,
• Caption,
• Annotation,
• Value
• Detail text
Some triggers
• Hover
• Write
• Click
Some functions:
• Stroke a path;
Certification
25) Certification