DAVIX
Encyclopedia
DAVIX is a Live CD
Live CD
A live CD, live DVD, or live disc is a CD or DVD containing a bootable computer operating system. Live CDs are unique in that they have the ability to run a complete, modern operating system on a computer lacking mutable secondary storage, such as a hard disk drive...

 based on Slackware
Slackware
Slackware is a free and open source Linux-based operating system. It was one of the earliest operating systems to be built on top of the Linux kernel and is the oldest currently being maintained. Slackware was created by Patrick Volkerding of Slackware Linux, Inc. in 1993...

 for the purposes of computer security
Computer security
Computer security is a branch of computer technology known as information security as applied to computers and networks. The objective of computer security includes protection of information and property from theft, corruption, or natural disaster, while allowing the information and property to...

 operations. The distribution focuses on data analysis and visualization . DAVIX stands for Data Analysis and VIsualization linuX. It is the first Live CD to integrate so many visualization tools. The long-term goal for the distribution is to provide a good set of tools supporting the complete process of visual data analysis.

Jan Monsch began work on the CD in December 2007. After discussions with Raffael Marty in January 2008, Jan agreed to produce the CD for "Applied Security Visualization" based on a list of utilities Raffael had discussed in the book.

Features

DAVIX contains a collection of more than 25 free tools for data processing and visualization . Some examples of the tools are:
  • Data Capture
    Packet sniffer
    A packet analyzer is a computer program or a piece of computer hardware that can intercept and log traffic passing over a digital network or part of a network...

     - tcpdump
    Tcpdump
    tcpdump is a common packet analyzer that runs under the command line. It allows the user to intercept and display TCP/IP and other packets being transmitted or received over a network to which the computer is attached...

    , PADS, p0f
    P0f
    p0f is a versatile passive OS fingerprinting tool. p0f can identify the system on machines that connect to your box, machines you connect to, and even machines that merely go through or near your box even if the device is behind a packet firewall....

    , Snort (software)
    Snort (software)
    Snort is a free and open source network intrusion prevention system and network intrusion detection system , created by Martin Roesch in 1998...

    , Wireshark
    Wireshark
    Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education...

  • Data Processing - Chaosreader, GeoIP, tcpreplay
  • Data Visualization
    Data visualization
    Data visualization is the study of the visual representation of data, meaning "information that has been abstracted in some schematic form, including attributes or variables for the units of information"....

     - AfterGlow, Cytoscape
    Cytoscape
    Cytoscape is an open source bioinformatics software platform for visualizing molecular interaction networks and integrating with gene expression profiles and other state data. Additional features are available as plugins...

    , Graphviz
    Graphviz
    Graphviz is a package of open-source tools initiated by AT&T Labs Research for drawing graphs specified in DOT language scripts. It also provides libraries for software applications to use the tools...

    , MRTG, R Project, TimeSearcher, TNV


The DAVIX CD ships with a 15 chapter manual which covers DAVIX use and customization with examples and screenshots. Additionally, most utilities on the system have documentation pages.

The DAVIX CD is based on Slax
SLAX
Slax is a LiveCD Linux distribution based on Slackware and is currently being developed by Tomáš Matějíček. Packages can be selected in a website where users can build a custom Slax iso image. Slax slogan refers to the software as a "Pocket Operating System"...

.

Security visualization

Computer information security visualization is a form of Visualization (computer graphics). In enterprise environments, computer security information can be generated in very large volumes, which can become very difficult to analyze without a visual context. Using DAVIX, a security engineer can visually spot anomalies in network traffic such as changes in IP sources/destinations, network protocols, application protocols, traffic patterns, frequency, and volume.

External links

The source of this article is wikipedia, the free encyclopedia.  The text of this article is licensed under the GFDL.
 
x
OK