• DocumentCode
    2858195
  • Title

    The design of VisFlowConnect-IP: a link analysis system for IP security situational awareness

  • Author

    Yin, Xiaoxin ; Yurcik, William ; Slagell, Adam

  • Author_Institution
    National Center for Supercomput. Applications, Illinois Univ., Urbana, IL, USA
  • fYear
    2005
  • fDate
    23-24 March 2005
  • Firstpage
    141
  • Lastpage
    153
  • Abstract
    Visualization of IP-based traffic dynamics on networks is a challenging task due to large data volume and the complex, temporal relationships between hosts. We present the architecture of VisFlowConnect-IP, a powerful new tool to visualize IP network traffic flow dynamics for security situational awareness. VisFlowConnect-IP allows an operator to visually assess the connectivity of large and complex networks on a single screen. It provides an overall view of the entire network and filter/drill-down features that allow operators to request more detailed information. Preliminary reports from several organizations using this tool report increased responsiveness to security events as well as new insights into understanding the security dynamics of their networks. In this paper we focus specifically on the design decisions made during the VisFlowConnect development process so that others may learn from our experience. The current VisFlowConnect architecture - the result of these design decisions - is extensible to processing other high-volume multi-dimensional data streams where link connectivity/activity is a focus of study. We report experimental results quantifying the scalability of the underlying algorithms for representing link analysis given continuous high-volume traffic flows as input.
  • Keywords
    IP networks; data communication; inter-computer links; security of data; telecommunication links; telecommunication security; telecommunication traffic; transport protocols; IP security situational awareness; IP-based traffic dynamics visualization; Netflow; VisFlowConnect-IP architecture; computer networks; high-volume multidimensional data stream processing; link activity; link analysis system; link connectivity; network connectivity; network security dynamics; security events; temporal relationships; Complex networks; Data security; Data visualization; Delay; IP networks; Information filtering; Information filters; Information security; Power system security; Telecommunication traffic; NetFlow; link analysis; security situational awareness; security visualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance, 2005. Proceedings. Third IEEE International Workshop on
  • Print_ISBN
    0-7695-2317-X
  • Type

    conf

  • DOI
    10.1109/IWIA.2005.17
  • Filename
    1410709