2020 IEEE Symposium on Visualization for Cyber Security (VizSec) 2020
DOI: 10.1109/vizsec51108.2020.00008
|View full text |Cite
|
Sign up to set email alerts
|

Exploratory Analysis of File System Metadata for Rapid Investigation of Security Incidents

Abstract: Figure 1: FIMETIS is a tool providing an interactive exploration of file system snapshots. Analysts can quickly investigate cybersecurity incidents via three complementary views: Alist view with file system records, Bhistogram with a timeline, and C -data clusters.

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
3
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
3
2
1

Relationship

0
6

Authors

Journals

citations
Cited by 6 publications
(4 citation statements)
references
References 19 publications
0
3
0
Order By: Relevance
“…Para analisar as recomendac ¸ões de mitigac ¸ão, é importante apresentar interfaces para o usuário ou gráficos de ataques. Os autores de [Beran et al 2020] criaram um banco de dados a partir de computadores afetados por incidentes, dividindo-o em um conjunto de demonstrac ¸ão da ferramenta e outro para avaliac ¸ão. Por meio de métodos analíticos, foram analisados os timestamps para avaliar as alterac ¸ões nos arquivos por meio da hora, o que resultou em um aplicativo, o Filesystem Metadata Analysis (FIMETIS).…”
Section: Métodos De Recomendac ¸ãO De Mitigac ¸ãOunclassified
“…Para analisar as recomendac ¸ões de mitigac ¸ão, é importante apresentar interfaces para o usuário ou gráficos de ataques. Os autores de [Beran et al 2020] criaram um banco de dados a partir de computadores afetados por incidentes, dividindo-o em um conjunto de demonstrac ¸ão da ferramenta e outro para avaliac ¸ão. Por meio de métodos analíticos, foram analisados os timestamps para avaliar as alterac ¸ões nos arquivos por meio da hora, o que resultou em um aplicativo, o Filesystem Metadata Analysis (FIMETIS).…”
Section: Métodos De Recomendac ¸ãO De Mitigac ¸ãOunclassified
“…To help analysts during security investigations, many visualisation tools have been proposed by the research community to analyse various event data such as network logs [32,8], DNS logs [29], system logs [15,16] or file system metadata [3]. These methods allow a faster and easier investigation giving the analyst the possibility to query and visualise large amount of complex data.…”
Section: Related Workmentioning
confidence: 99%
“…To complement IDSs, visualisation tools [13,31,12,8,32,3] have been developped to identify attacks in the data. Among those tools, some have focused on log visualisation [15,16].…”
Section: Introductionmentioning
confidence: 99%
“…FIMETIS is a tool allowing to interactively explore file system snapshots [1]. The tool provides a security analyst with simple and straightforward analysis views for file system records, the temporal sequence of events, and data clusters.…”
Section: Related Workmentioning
confidence: 99%