Security Visualization

Security Operations and Security Event Analysis effectiveness can be greatly improved through visualizing security event data. While some people take great please in looking at long lists of statistics from firewalls, intrusion detection systems and other security related logs most find it not only boring but also ineffective.

Visualizing the data can help an analyst spot patterns and trends that may otherwise be missed. It also makes your reports look pretty. ;)

An excellent resource on visualization (not only security focused) with a collection of examples is the Flowing Data Blog. A more security focused site is the SecViz project.

While I am only getting started and playing around, I plan on doing a few pages showing some examples of easy to use and build visualizations.

SSH Blacklist Visualization
Tor Exit Node Visualization
Web Server Survey Summary
CMS Survey Summary