In order to provide a technology, when an access having the possibility of a threatening factor according to an access failure is detected, for collecting information about the access to intuitively display the
route of the threatening behavior on an interface that outputs the
server-terminal connection network, and directly replaying the threatening behavior to intuitively identify the information on the access and easily identify a cause of the
threat, a method for visualizing a
route and a behavior of a user by linking a security
threat and a
security kernel of a
server-terminal connection network according to one embodiment of the present invention includes: an access detection step of setting a plurality of terminals, servers accessible from the terminals, and communication
processing devices between the terminals and the servers as nodes, and detecting an attempt to access one
server from one terminal in a server-terminal connection network including a
route on the network connecting the set nodes as links; a log collection step, based on the access detected in the access detection step, of collecting log information generated when the one terminal attempts to access; and a
visualization step, when a
visualization request input for the log information collected in the log collection step is received from an administrator terminal, of visualizing the nodes, the links and the log information on a
visualization interface executed in the administrator terminal, wherein the visualization step, with respect to the log information on access failure, includes using the log information to display a node including a terminal attempting the access and a server to be accessed and links between nodes, and a visual effect indicating failure of log information, on the visualization screen of the server-terminal connection
network on the visualization interface.