|
Visualisation of Honeypot Data Using Graphiz and Afterglow
Craig Valli
secau – Security Research Centre
Edith Cowan University
c.valli@ecu.edu.au
ABSTRACT
This research in progress paper
explores the use of Graphviz and Afterglow for the analysis of
data emanating from a honeypot system. Honeypot systems gather a
wide range of data that is often difficult to readily search for
patterns and trends using conventional log file analysis
techniques. The data from the honeypots has been statically
extracted and processed through Afterglow scripts to produce
inputs suitable for use by the DOT graph based tools contained
within Graphviz. This paper explores some of the benefits and
drawbacks of currently using this type of approach.
Keywords: honeypot, network forensics, visualization,
Graphviz, Afterglow
|