2005Conference on Designing for User ExperienceRequires access

Damming the flood: monitoring streaming security event data using BlockTables

Andreas Dieberger, Markus Stolze, René Pawlitzek

Open publisher page 0 citations

Abstract

Security Event Monitoring is a tedious job where users stare at long tables of incoming security events indicating potential threats. Most of the events, however, are false alarms and the user has to find these and dismiss them. This paper talks about design changes in a security event monitoring tool, called the ZEC (Zurich Event Console) which, based on findings in a usability study and observations of how event monitors go about their job, are meant to make them more efficient. In particular, BlockTables are designed to make the inherent structure of event data more apparent. We also describe the design of a navigation feature which allows users to navigate the event table based on the inherent block structure exposed by the BlockTables.

About this research paper

What this paper is about

Security Event Monitoring is a tedious job where users stare at long tables of incoming security events indicating potential threats. Most of the events, however, are false alarms and the user has to find these and dismiss them. This paper talks about design changes in a security event monitoring tool, called the ZEC (Zurich Event Console) which, based on findings in a usability study and observations of how event monitors go about their job, are meant to make them more efficient. In particular, BlockTables are designed to make the inherent structure of event data more apparent. We also describe the design of a navigation feature which allows users to navigate the event table based on the inherent block structure exposed by the BlockTables.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Security Event Monitoring is a tedious job where users stare at long tables of incoming security events indicating potential threats. Most of the events, however, are false alarms and the user has to find these and dismiss them. This paper talks about design changes in a security event monitoring tool, called the ZEC (Zurich Event Console) which, based on findings in a usability study and observations of how event monitors go about their job, are meant to make them more efficient. In particular, BlockTables are designed to make the inherent structure of event data more apparent. We also describe the design of a navigation feature which allows users to navigate the event table based on the inherent block structure exposed by the BlockTables.

Key concepts: Event (particle physics), Computer science, Usability, Flood myth, Event data, Table (database), Complex event processing, Computer security

Related papers

Back to paper searchBrowse research topicsOriginal source
Damming the flood: monitoring streaming security event data using BlockTables — Research Paper | ScholarLens