TY - GEN
T1 - Worm path identification using visualization system
AU - Shibaguchi, Seiji
AU - Nakayama, Yuki
AU - Okada, Ken Ichi
PY - 2009/12/4
Y1 - 2009/12/4
N2 - In this paper, we propose a visualization system for worm investigation, which finds worm origins and worm paths. Although investigation of worms are very important for forensic use and further prevention, it is quite difficult for automatic systems to identify worm origins or paths due to the trade-off between false positives and false negatives. Therefore, we focused on interaction between analysts and connection logs. At first, an automated algorithm is run so that there are no false negatives, and then analysts investigate the result to reduce false positives by visualized system. We aim to solve the trade-off by conducting these two steps. We implemented a prototype and conducted a user experiment to evaluate our system. The results show our system enabled subjects to reduce 90% of false detection by an automated algorithm. Although the results depend on parameters or conditions, we show the effectiveness of our idea.
AB - In this paper, we propose a visualization system for worm investigation, which finds worm origins and worm paths. Although investigation of worms are very important for forensic use and further prevention, it is quite difficult for automatic systems to identify worm origins or paths due to the trade-off between false positives and false negatives. Therefore, we focused on interaction between analysts and connection logs. At first, an automated algorithm is run so that there are no false negatives, and then analysts investigate the result to reduce false positives by visualized system. We aim to solve the trade-off by conducting these two steps. We implemented a prototype and conducted a user experiment to evaluate our system. The results show our system enabled subjects to reduce 90% of false detection by an automated algorithm. Although the results depend on parameters or conditions, we show the effectiveness of our idea.
UR - http://www.scopus.com/inward/record.url?scp=70849118929&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=70849118929&partnerID=8YFLogxK
U2 - 10.1109/CSE.2009.340
DO - 10.1109/CSE.2009.340
M3 - Conference contribution
AN - SCOPUS:70849118929
SN - 9780769538235
T3 - Proceedings - 12th IEEE International Conference on Computational Science and Engineering, CSE 2009
SP - 498
EP - 503
BT - Proceedings - 12th IEEE International Conference on Computational Science and Engineering, CSE 2009 - 2009 IEEE International Conference on Privacy, Security, Risk, and Trust, PASSAT 2009
T2 - 2009 IEEE International Conference on Privacy, Security, Risk, and Trust, PASSAT 2009
Y2 - 29 August 2009 through 31 August 2009
ER -