Title
User Behavior Map: Visual Exploration for Cyber Security Session Data
Abstract
User behavior analysis is complex and especially crucial in the cyber security domain. Understanding dynamic and multi-variate user behavior are challenging. Traditional sequential and timeline based method cannot easily address the complexity of temporal and relational features of user behaviors. We propose a map-based visual metaphor and create an interactive map for encoding user behaviors. It enables analysts to explore and identify user behavior patterns and helps them to understand why some behaviors are regarded as anomalous. We experiment with a real dataset containing multiple user sessions, consisting of sequences of diverse types of actions. In the behavior map, we encode an action as a city and user sessions as trajectories going through the cities. The position of the cities is determined by the sequential and temporal relationship of actions. Spatial and temporal patterns on the map reflect behavior patterns in the action space. In the case study, we illustrate how we explore relationships between actions, identify patterns of the typical session and detect anomaly behaviors.
Year
DOI
Venue
2018
10.1109/VIZSEC.2018.8709223
2018 IEEE Symposium on Visualization for Cyber Security (VizSec)
Keywords
Field
DocType
Behavior Analysis,Map Metaphor,Cyber Security
ENCODE,Data visualization,Task analysis,Computer security,Computer science,Visual analytics,Timeline,Trajectory,Metaphor,Encoding (memory)
Conference
ISSN
ISBN
Citations 
2639-4359
978-1-5386-8195-4
2
PageRank 
References 
Authors
0.44
9
8
Name
Order
Citations
PageRank
Siming Chen112514.34
Shuai Chen2339.17
Natalia Andrienko32922192.14
Gennady Andrienko43106208.19
Phong H. Nguyen5807.37
Cagatay Turkay628722.63
Olivier Thonnard723019.56
Xiaoru Yuan8115770.28