DocumentCode :
2408850
Title :
Exploring three-dimensional visualization for intrusion detection
Author :
Oline, Adam ; Reiners, Dirk
Author_Institution :
Dept. of Comput. Sci., Iowa State Univ., USA
fYear :
2005
fDate :
26 Oct. 2005
Firstpage :
113
Lastpage :
120
Abstract :
Intrusion detection systems have been popular tools in the battle against adversaries who, for whatever reason, desire to break into networks, compromise hosts, and steal valuable information. One problem with current implementations, however, is the sheer number of alerts they can generate, many of which tend to be false alarms. This drawback makes effective use of such systems a challenging task. In this paper we explore three-dimensional approaches to visualizing network intrusion detection system alerts and aggregated network statistics in order to provide the system administrator with a better picture of the events occurring on his or her network. While some research has been done using two-dimensional concepts, 3D approaches have not received much attention with regard to detecting network intrusions. Evaluation of our visualizations using the 1999 DARPA intrusion detection evaluation data set demonstrates the potential benefit of utilizing the third dimension. We show how a number of attack types in the data set generate visual evidence of abnormal activity that a security administrator might use as motivation for further investigation.
Keywords :
data visualisation; security of data; 1999 DARPA intrusion detection evaluation data set; abnormal network activity; aggregated network statistics; data reduction; network intrusion detection system; three-dimensional visualization; visual evidence generation; Computer interfaces; Computer network management; Computer networks; Computer security; Data security; Data visualization; Graphical user interfaces; Information security; Intrusion detection; Protection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Visualization for Computer Security, 2005. (VizSEC 05). IEEE Workshop on
Print_ISBN :
0-7803-9477-1
Type :
conf
DOI :
10.1109/VIZSEC.2005.1532073
Filename :
1532073
Link To Document :
بازگشت