2014 · 2014 IEEE 27th Canadian Conference on Electrical and Computer Engineering (CCECE)
Multiscale Navigation in Large Trace Data
Evidence basis: full-text-reviewed · Review status: catalog-reviewed; paper-author approval pending
trace-visualization trace-abstraction trace-analysis performance-analysis
large trace data multiscale navigation zoomable timeline semantic zoom physical zoom trace visualization
Core contribution: The paper presents multiscale trace navigation that links raw kernel events to system-call, synthetic, and fault/alert abstractions in a zoomable timeline.
Catalog abstract summary
The accessible abstract describes hierarchical trace-log management with an interactive zoomable timeline and semantic and physical zooming that supports coarse-layer-first navigation.
Source: Public abstract mirrors and institutional metadata reviewed; author abstract not reproduced because reuse permission for the publisher version was not established.
Problem and motivation
A single-resolution view of a large execution trace either overwhelms the analyst with low-level events or hides the evidence needed to explain a high-level operation. Analysts need overview, drill-down, and correspondence between abstraction levels.
Method and contribution
The prototype uses LTTng 1.x on Linux kernel 2.6.38.6 and builds abstraction layers from raw kernel events to system calls, synthetic HTTP/file/DNS/attack events, and faults/alerts. A pattern library applies aggregation, generalization, filtering, and reduction. Events are linked through process names and time bounds, and a zoomable timeline supports physical/semantic zoom and range queries. A customized disk-backed State History Tree stores the layers separately, with hybrid on-demand/precomputed aggregation proposed for the storage/query trade-off. The example workload recursively downloads dnews.com on an Intel Core i7 2.8 GHz/6 GB system.
Findings and evidence
The prototype demonstrates a single view in which a high-level file download can be expanded into DNS/HTTP events and then kernel system calls, preserving a path for causal inspection. Precomputing levels can speed visualization at the cost of storage, while on-demand abstraction saves space but adds query work. The paper does not report a broad quantitative accuracy or interaction-latency benchmark.
Limitations and future directions
Limitations: The abstraction hierarchy and link logic are tied to the demonstrated patterns, layers are stored separately, and direct correspondence pointers are limited. The evaluation uses a prototype and one main workload, so performance and usability at much larger traces remain open.
Future work: Integrate abstraction levels in one efficient store, add explicit event correspondence, learn or configure links from data, evaluate hybrid aggregation policies, and measure storage, query latency, and human navigation quality at scale.
Sources and identifiers
- Published version published
- PolyPublie record public_source_record
When to cite this paper
Cite this paper when linking overview-to-detail navigation across abstracted and raw execution-trace levels.
- LTTng raw/system-call/synthetic/fault abstraction layers.
- Time-bound and process-linked correspondence between levels.
- The zoomable timeline and disk-backed State History Tree.
- The storage-versus-query-time trade-off and prototype-scale limitation.
Citation
@inproceedings{ezzatiJivan2014multiscalenavigation,
author = {Naser Ezzati-Jivan and Michel R. Dagenais},
title = {Multiscale Navigation in Large Trace Data},
year = {2014},
booktitle = {2014 IEEE 27th Canadian Conference on Electrical and Computer Engineering (CCECE)},
pages = {1-7},
publisher = {IEEE},
doi = {10.1109/CCECE.2014.6901019},
url = {https://doi.org/10.1109/CCECE.2014.6901019}
}Other citation formats for Word and reference managers
Ezzati-Jivan, N., & Dagenais, M. R. (2014). Multiscale Navigation in Large Trace Data. In 2014 IEEE 27th Canadian Conference on Electrical and Computer Engineering (CCECE) (pp. 1-7). https://doi.org/10.1109/CCECE.2014.6901019N. Ezzati-Jivan and M. R. Dagenais, "Multiscale Navigation in Large Trace Data," in 2014 IEEE 27th Canadian Conference on Electrical and Computer Engineering (CCECE), pp. 1-7, 2014, doi: 10.1109/CCECE.2014.6901019