Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
Research Projects
SHARE

SECURITY EVENT VISUALIZATION AND ANALYSIS



Assessing and monitoring the information security posture of a system composed of a multitude of technologies and critical applications is a challenging task for even the most experienced professional team. While today's event visualization solutions strive to be comprehensive, they are of limited use as their information often cannot effectively be accessed and analyzed to provide value.

To help security practitioners better understand the volume of information presented to them, the CoreLabs team has developed a security visualization technology, that collates and interprets all relevant security information and then presents it in simple, ease-to-use and understand graphical formats.

In 2002, we assembled a workshop uniting a team of over 30 inter-disciplinary researchers working in six special interest groups to research this topic. The workshop focused on early detection and forensic analysis of common attacks in cyberwarfare and medium-scale network attack scenarios. The study was based on a sample network of medium complexity, deploying industry-leading technologies such as firewalls and a variety of intrusion detection systems (IDS). These groups were tasked with both developing new forms of attacks that would thwart current systems and developing new visualization technologies to detect and visually represent these attacks.

In previous projects, CoreLabs has produced related technologies (i.e. Msyslog) that provide a tamper-proof repository of log information, improving the integrity of data used to detect and visualize attacks.

Project Resources:



CORE WISDOM v1.0 (25.4 MB)



CORE WISDOM v1.0 User Guide (4.9 MB)

CORE WISDOM v1.8 (26.1 MB)

 



About CORE WISDOM

CORE WISDOM is a suite of tools designed for the secure auditing of information systems.

CORE WISDOM centralizes and guarantees the integrity of system logs and significantly improves the auditing of security information systems by processing and representing the information in unique graphical ways.

In order to provide the most comprehensive monitoring of system events and to ensure the highest level of information resource availability, CORE WISDOM both coordinates and archives historical log data for forensic analysis, and displays all events in real-time, allowing high availability of information resources. The suite centralizes logging and reporting needs in such a way as to improve the potential of the most powerful tool: the mind.


« Back to Projects List

Related Content