research

Visual Analytics of Event Data using Multiple Mining Methods

Abstract

Most researchers use a single method of mining to analyze event data. This paper uses case studies from two very differentdomains (electronic health records and cybersecurity) to investigate how researchers can gain breakthrough insights by com-bining multiple event mining methods in a visual analytics workflow. The aim of the health case study was to identify patternsof missing values, which was daunting because the 615 million missing values occurred in 43,219 combinations of fields. How-ever, a workflow that involved exclusive set intersections (ESI), frequent itemset mining (FIM) and then two more ESI stepsallowed us to identify that 82% of the missing values were from just 244 combinations. The cybersecurity case study’s aim wasto understand users’ behavior from logs that contained 300 types of action, gathered from 15,000 sessions and 1,400 users.Sequential frequent pattern mining (SFPM) and ESI highlighted some patterns in common, and others that were not. For thelatter, SFPM stood out for its ability to action sequences that were buried within otherwise different sessions, and ESI detectedsubtle signals that were missed by SFPM. In summary, this paper demonstrates the importance of using multiple perspectives,complementary set mining methods and a diverse workflow when using visual analytics to analyze complex event data

    Similar works