SiMEVis – SimilarityMap Event Visualization

New Visualization Methods for the Analysis of IT Security Events

SiMEVis (SimilarityMap Event Visualization) is a two-year technology demonstrator funded by the Hessian Ministry of the Interior, for Security and Homeland Protection (HMDI). In collaboration with its application partner ekom21, Fraunhofer IGD developed innovative methods for the interactive analysis and visualization of IT security events generated by Security Information and Event Management (SIEM) systems.

Efficient SIEM Alert Analysis for Faster IT Security Incident Assessment

Security analysts face an overwhelming number of alerts from SIEM systems every day. Many of these alerts are highly similar but still require individual assessment, increasing the effort required for analysis, documentation, and onboarding new personnel.

SiMEVis aims to automatically identify similar security events and group them visually. This enables analysts to recognize recurring attack patterns more quickly and assess new security incidents more efficiently.

Cybersecurity dashboard visualizing alerts, risks, and event analysis.

Interactive Visualization and Similarity-Based Analysis of SIEM Alerts

At the heart of the project is an interactive similarity analysis of security alerts over extended periods of time. Security events are compared based on their characteristics and displayed using an intuitive visualization. This allows analysts to immediately identify incidents that resemble previously investigated cases and to see which response measures proved successful in comparable situations.

The developed prototype also supports the quality management of alert definitions. Recurring patterns and opportunities to optimize detection rules can be identified more easily.

Integration into Existing Security Infrastructures

A key advantage of SiMEVis is its open system architecture.

The prototype can be connected via standardized APIs to event and alert data from virtually all common SIEM platforms. At the same time, links to the original data remain within the respective SIEM system, allowing existing workflows to continue unchanged.

In addition, case management platforms such as TheHive can be integrated. This enables documented response procedures from previous security incidents to be incorporated directly into the similarity analysis. As a result, new alerts can be processed more efficiently while also supporting the onboarding of new staff in Security Operations Centers (SOCs).

Project Partners

The project was carried out jointly by:

  • Fraunhofer Institute for Computer Graphics Research IGD
  • ekom21 – KGRZ Hessen

Funding

SiMEVis was funded under the Cyber and IT Security Research Program of the Hessian Ministry of the Interior, for Security and Homeland Protection (HMDI).

Hesse Cybersecurity Research Funding & ekom21 company logo

SiMEVis - SimilarityMap Event Visualization demo video

Privacy warning

With the click on the play button an external video from www.youtube.com is loaded and started. Your data is possible transferred and stored to third party. Do not start the video if you disagree. Find more about the youtube privacy statement under the following link: https://policies.google.com/privacy

SiMEVis - SimilarityMap Event Visualization Demo