Proceedings of the Symposium on Computer Human Interaction for the Management of Information Technology 2009
DOI: 10.1145/1641587.1641590
|View full text |Cite
|
Sign up to set email alerts
|

Visual support for analyzing network traffic and intrusion detection events using TreeMap and graph representations

Abstract: Network security depends heavily on automated Intrusion Detection Systems (IDS) to sense malicious activity. Unfortunately, IDS often deliver both too much raw information, and an incomplete local picture, impeding accurate assessment of emerging threats. We propose a system to support analysis of IDS logs, that visually pivots large sets of Net-Flows. In particular, two visual representations of the flow data are compared: a TreeMap visualization of local network hosts, which are linked through hierarchical e… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
25
0

Year Published

2011
2011
2015
2015

Publication Types

Select...
5
3
1

Relationship

0
9

Authors

Journals

citations
Cited by 42 publications
(26 citation statements)
references
References 18 publications
0
25
0
Order By: Relevance
“…As in this study, the tool uses automated processes to direct users' attention, and the authors observe that automation failures inhibit users' understanding. In another system targeted at network diagnosis, Mansmann et al observe that automated tools alone are limited in utility without effective presentation of results [26]. Like many other network monitoring efforts, however, the proposed solution primarily focuses on improving display of the underlying data rather than the output of an automated tool.…”
Section: Visualization For System Diagnosismentioning
confidence: 99%
See 1 more Smart Citation
“…As in this study, the tool uses automated processes to direct users' attention, and the authors observe that automation failures inhibit users' understanding. In another system targeted at network diagnosis, Mansmann et al observe that automated tools alone are limited in utility without effective presentation of results [26]. Like many other network monitoring efforts, however, the proposed solution primarily focuses on improving display of the underlying data rather than the output of an automated tool.…”
Section: Visualization For System Diagnosismentioning
confidence: 99%
“…Though complete automation would be ideal, the complexity of modern systems and the problems that arise in them ensure that this human-in-the-loop model will be dominant for the foreseeable future. As such, many researchers recognize the need for localization tools to present their results as clearly as possible [26,29]. But apart from from a few select instances [23,26], little research has been conducted on how to do so.…”
Section: Introductionmentioning
confidence: 99%
“…However, such layouts are highly application dependent. Additional work has been done in attempts to understand flow across a network by comparing graph-based flow visualization with TreeMaps for local network monitoring [19]. Here too, both the problem space and necessary analysis techniques are highly application dependent.…”
Section: Visualizations Of Network Trafficmentioning
confidence: 99%
“…By dividing the display area into a nested sequence of rectangles whose areas are associated to attributes of the data set, it effectively illustrates the structural information with slices and dices. TreeMaps have been applied to a wide variety of domains ranging from financial analysis [23], petroleum engineering [24] to network security analysis [25]. Some studies have focused on specialized techniques to visualize large number items on a TreeMap without aggregation [26].…”
Section: Treemapsmentioning
confidence: 99%