TY - CHAP U1 - Konferenzveröffentlichung A1 - Ahlers, Volker A1 - Hellmann, Bastian A1 - Dreo Rodosek, Gabi T1 - A user study of the visualization-assisted evaluation and management of network security detection events and policies T2 - 2019 10th IEEE International Conference on Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications (IDAACS) N2 - Intrusion detection systems and other network security components detect security-relevant events based on policies consisting of rules. If an event turns out as a false alarm, the corresponding policy has to be adjusted in order to reduce the number of false positives. Modified policies, however, need to be tested before going into productive use. We present a visual analysis tool for the evaluation of security events and related policies which integrates data from different sources using the IF-MAP specification and provides a “what-if” simulation for testing modified policies on past network dynamics. In this paper, we will describe the design and outcome of a user study that will help us to evaluate our visual analysis tool. KW - Network Security KW - User Interfaces KW - Visualization KW - Information Visualization KW - Rechnernetz KW - Computersicherheit KW - Benutzeroberfläche KW - Visualisierung Y1 - 2019 UN - https://nbn-resolving.org/urn:nbn:de:bsz:960-opus4-21548 SN - 978-1-7281-4069-8 SB - 978-1-7281-4069-8 U6 - https://doi.org/10.25968/opus-2154 DO - https://doi.org/10.25968/opus-2154 SP - 668 EP - 673 PB - IEEE ER -