Workshop: Big Data Visualization for Security

I had the pleasure of attending the Underground Economy Conference this year in Bucharest, Romania. I ran a 90 minute workshop on big data and visualization. The workshop covered a number of tools, such as:

Firewall Log in Gephi


Here are the slides from the workshop [Well, almost all of them. Having attended the workshop, you will have seen some more]. In addition, you can download the DAVIX image that you need for the exercise.

Firewall Log in Gephi

Firewall Log in Gephi

Firewall log where nodes encode the source and destination machines. The edge colors encode the port used for the communication. Graph was created by using AfterGlow and Gephi for the rendering.
On the left hand side, you can see DNS traffic, the brown part. The red edges denote SMTP traffic.

IPv4 LAN Traffic on a host visualized with tnv

IPv4 LAN Traffic on a host visualized with tnv

http://tnv.sourceforge.net/

Visual Analytics Workshop - Link Collection Part V - Big Data

This next module of the Visual Analytics Workshop is about Big Data. And here are the links that show up during this section. Keep in mind that especially this module is constantly evolving and has in the last months. New sections and links will be added to the training class very frequently.

Looking for the previous list of links for the workshop?

- Introductionary Links
- Data Sources
- Data Processing
- Log Management and SIEM

Wanna know more about the visualization workshop? Email me or visit http://pixlcloud.com/training

Stay tuned for the next link collection!

Visual Analytics Workshop - Link Collection Part IV - Log Management and SIEM

This is the Labor Day issue of the link collection series. The third module of the Visual Analytics Workshop is about Log Management and SIEM.

Looking for the previous list of links for the workshop?

- Introductionary Links
- Data Sources
- Data Processing

Wanna know more about the visualization workshop? Email me or visit http://pixlcloud.com/training

Stay tuned for the next link collection which will be on big data!

Gephi and afterglow of IPv4 LAN traffic

Gephi and afterglow of IPv4 LAN traffic

only a portion of the data was given to Gephi

LAN Traffic - Gephi

LAN Traffic - Gephi

LAN Traffic as seen from a workstation visualized using afterglow and Gephi. To get GDF format file for Gephi use the -k parameter with Afterglow. Thanks Raffy.

IPV6 multicast DNS Traffic

IPV6 multicast DNS Traffic

I guess tcpdump version 4.6.1 is not compatible with tcpdump2csv.pl hence I got only IPV6 traffic parsed to afterglow.

Visual Analytics Workshop - Link Collection Part III - Data Processing

Here is part three of the link collection series. The second module of the Visual Analytics Workshop is about Log Data Processing.

- CommandlineFu
- Regex Lib
- Regular Expressio Information
- Regex One
- RegExr
- Geo Lookup On The Commandline
- Log Analysis Scripts
- DAVIX
- httpry
- dnstop
- Emerging Threats
- HoneySnap
- LogParser
- LogParser Studio

Looking for the previous list of links for the workshop?

- Introductionary Links
- Data Sources

Wanna know more about the visualization workshop? Email me or visit http://pixlcloud.com/training

Next workshop is in Amsterdam

IPV4 LAN

IPV4 LAN

A view of IPV4 LAN traffic as seen from one of the servers made with tcpdump and pcap using afterglow