DocumentCode
2858195
Title
The design of VisFlowConnect-IP: a link analysis system for IP security situational awareness
Author
Yin, Xiaoxin ; Yurcik, William ; Slagell, Adam
Author_Institution
National Center for Supercomput. Applications, Illinois Univ., Urbana, IL, USA
fYear
2005
fDate
23-24 March 2005
Firstpage
141
Lastpage
153
Abstract
Visualization of IP-based traffic dynamics on networks is a challenging task due to large data volume and the complex, temporal relationships between hosts. We present the architecture of VisFlowConnect-IP, a powerful new tool to visualize IP network traffic flow dynamics for security situational awareness. VisFlowConnect-IP allows an operator to visually assess the connectivity of large and complex networks on a single screen. It provides an overall view of the entire network and filter/drill-down features that allow operators to request more detailed information. Preliminary reports from several organizations using this tool report increased responsiveness to security events as well as new insights into understanding the security dynamics of their networks. In this paper we focus specifically on the design decisions made during the VisFlowConnect development process so that others may learn from our experience. The current VisFlowConnect architecture - the result of these design decisions - is extensible to processing other high-volume multi-dimensional data streams where link connectivity/activity is a focus of study. We report experimental results quantifying the scalability of the underlying algorithms for representing link analysis given continuous high-volume traffic flows as input.
Keywords
IP networks; data communication; inter-computer links; security of data; telecommunication links; telecommunication security; telecommunication traffic; transport protocols; IP security situational awareness; IP-based traffic dynamics visualization; Netflow; VisFlowConnect-IP architecture; computer networks; high-volume multidimensional data stream processing; link activity; link analysis system; link connectivity; network connectivity; network security dynamics; security events; temporal relationships; Complex networks; Data security; Data visualization; Delay; IP networks; Information filtering; Information filters; Information security; Power system security; Telecommunication traffic; NetFlow; link analysis; security situational awareness; security visualization;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Assurance, 2005. Proceedings. Third IEEE International Workshop on
Print_ISBN
0-7695-2317-X
Type
conf
DOI
10.1109/IWIA.2005.17
Filename
1410709
Link To Document