2014 · 2014 IEEE 27th Canadian Conference on Electrical and Computer Engineering (CCECE)

Multiscale Navigation in Large Trace Data

Naser Ezzati-Jivan | Michel R. Dagenais

Evidence basis: full-text-reviewed · Review status: catalog-reviewed; paper-author approval pending

trace-visualization trace-abstraction trace-analysis performance-analysis

large trace data multiscale navigation zoomable timeline semantic zoom physical zoom trace visualization

Core contribution: The paper presents multiscale trace navigation that links raw kernel events to system-call, synthetic, and fault/alert abstractions in a zoomable timeline.

Catalog abstract summary

The accessible abstract describes hierarchical trace-log management with an interactive zoomable timeline and semantic and physical zooming that supports coarse-layer-first navigation.

Source: Public abstract mirrors and institutional metadata reviewed; author abstract not reproduced because reuse permission for the publisher version was not established.

Problem and motivation

A single-resolution view of a large execution trace either overwhelms the analyst with low-level events or hides the evidence needed to explain a high-level operation. Analysts need overview, drill-down, and correspondence between abstraction levels.

Method and contribution

The prototype uses LTTng 1.x on Linux kernel 2.6.38.6 and builds abstraction layers from raw kernel events to system calls, synthetic HTTP/file/DNS/attack events, and faults/alerts. A pattern library applies aggregation, generalization, filtering, and reduction. Events are linked through process names and time bounds, and a zoomable timeline supports physical/semantic zoom and range queries. A customized disk-backed State History Tree stores the layers separately, with hybrid on-demand/precomputed aggregation proposed for the storage/query trade-off. The example workload recursively downloads dnews.com on an Intel Core i7 2.8 GHz/6 GB system.

Findings and evidence

The prototype demonstrates a single view in which a high-level file download can be expanded into DNS/HTTP events and then kernel system calls, preserving a path for causal inspection. Precomputing levels can speed visualization at the cost of storage, while on-demand abstraction saves space but adds query work. The paper does not report a broad quantitative accuracy or interaction-latency benchmark.

Limitations and future directions

Limitations: The abstraction hierarchy and link logic are tied to the demonstrated patterns, layers are stored separately, and direct correspondence pointers are limited. The evaluation uses a prototype and one main workload, so performance and usability at much larger traces remain open.

Future work: Integrate abstraction levels in one efficient store, add explicit event correspondence, learn or configure links from data, evaluate hybrid aggregation policies, and measure storage, query latency, and human navigation quality at scale.

Sources and identifiers

When to cite this paper

Cite this paper when linking overview-to-detail navigation across abstracted and raw execution-trace levels.

  • LTTng raw/system-call/synthetic/fault abstraction layers.
  • Time-bound and process-linked correspondence between levels.
  • The zoomable timeline and disk-backed State History Tree.
  • The storage-versus-query-time trade-off and prototype-scale limitation.

Citation

BibTeX
@inproceedings{ezzatiJivan2014multiscalenavigation,
  author = {Naser Ezzati-Jivan and Michel R. Dagenais},
  title = {Multiscale Navigation in Large Trace Data},
  year = {2014},
  booktitle = {2014 IEEE 27th Canadian Conference on Electrical and Computer Engineering (CCECE)},
  pages = {1-7},
  publisher = {IEEE},
  doi = {10.1109/CCECE.2014.6901019},
  url = {https://doi.org/10.1109/CCECE.2014.6901019}
}
Other citation formats for Word and reference managers
APA 7
Ezzati-Jivan, N., & Dagenais, M. R. (2014). Multiscale Navigation in Large Trace Data. In 2014 IEEE 27th Canadian Conference on Electrical and Computer Engineering (CCECE) (pp. 1-7). https://doi.org/10.1109/CCECE.2014.6901019
IEEE
N. Ezzati-Jivan and M. R. Dagenais, "Multiscale Navigation in Large Trace Data," in 2014 IEEE 27th Canadian Conference on Electrical and Computer Engineering (CCECE), pp. 1-7, 2014, doi: 10.1109/CCECE.2014.6901019

Readable Markdown record · JSON record · Download RIS