1st International ICST Workshop on Enterprise Network Security

Research Article

Efficient visualization of change events in enterprise networks

  • @INPROCEEDINGS{10.1109/SECCOMW.2006.359582,
        author={Andrew  Stewart},
        title={Efficient visualization of change events in enterprise networks},
        proceedings={1st International ICST Workshop on Enterprise Network Security},
        publisher={IEEE},
        proceedings_a={WENS},
        year={2007},
        month={5},
        keywords={},
        doi={10.1109/SECCOMW.2006.359582}
    }
    
  • Andrew Stewart
    Year: 2007
    Efficient visualization of change events in enterprise networks
    WENS
    IEEE
    DOI: 10.1109/SECCOMW.2006.359582
Andrew Stewart1,*
  • 1: Equifax, P.O.Box 740006, Atlanta, GA 30374
*Contact email: andrew.stewart@equifax.com

Abstract

Change is a crucial property from a security perspective. The detection of change underpins many of the operational security activities that organizations typically carry out. For example, the essence of security monitoring is to detect changes, then analyze those changes in the context of the applicable security policy. Security tools are available to perform change detection at a host level. Such tools typically employ a local software agent, and identify changes that occur in the filesystem of the host. We describe a tool that performs a similar role in a network environment. The tool employs a variety of visualization techniques to efficiently communicate changes that occur in enterprise networks