• DocumentCode
    1706472
  • Title

    Real-time and forensic network data analysis using animated and coordinated visualization

  • Author

    Krasser, Sven ; Conti, Gregory ; Grizzard, Julian ; Gribschaw, Jeff ; Owen, Henry

  • Author_Institution
    Sch. of Electr. & Comput. Eng., eorgia Inst. of Technol., Atlanta, GA, USA
  • fYear
    2005
  • Firstpage
    42
  • Lastpage
    49
  • Abstract
    Rapidly detecting and classifying malicious activity contained within network traffic is a challenging problem exacerbated by large datasets and functionally limited manual analysis tools. Even on a small network, manual analysis of network traffic is inefficient and extremely time consuming. Current machine processing techniques, while fast, suffer from an unacceptable percentage of false positives and false negatives. To complement both manual and automated analysis of network traffic, we applied information visualization techniques to appropriately and effectively bring the human into the analytic loop. This paper describes the implementation and lessons learned from the creation of a novel network traffic visualization system capable of both realtime and forensic data analysis. Combining the strength of link analysis using parallel coordinate plots with the time-sequence animation of scatter plots, we examine a 2D and 3D coordinated display that provides insight into both legitimate and malicious network activity. Our results indicate that analysts can rapidly examine network traffic and detect anomalies far more quickly than with manual tools.
  • Keywords
    computer animation; computer networks; data analysis; data visualisation; pattern recognition; real-time systems; security of data; telecommunication security; 2D coordinated display; 3D coordinated display; analytic loop; animated visualization; anomaly detection; coordinated visualization; forensic network data analysis; honeynet visualization; honeypot visualization; information visualization; link analysis; malicious activity classification; malicious activity detection; network activity; network traffic visualization system; parallel coordinate plots; real-time network data analysis; scatter plots; security visualization; time-sequence animation; Animation; Data analysis; Data visualization; Forensics; Humans; Information analysis; Manuals; Scattering; Telecommunication traffic; Three dimensional displays;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance Workshop, 2005. IAW '05. Proceedings from the Sixth Annual IEEE SMC
  • Print_ISBN
    0-7803-9290-6
  • Type

    conf

  • DOI
    10.1109/IAW.2005.1495932
  • Filename
    1495932