DocumentCode
1706472
Title
Real-time and forensic network data analysis using animated and coordinated visualization
Author
Krasser, Sven ; Conti, Gregory ; Grizzard, Julian ; Gribschaw, Jeff ; Owen, Henry
Author_Institution
Sch. of Electr. & Comput. Eng., eorgia Inst. of Technol., Atlanta, GA, USA
fYear
2005
Firstpage
42
Lastpage
49
Abstract
Rapidly detecting and classifying malicious activity contained within network traffic is a challenging problem exacerbated by large datasets and functionally limited manual analysis tools. Even on a small network, manual analysis of network traffic is inefficient and extremely time consuming. Current machine processing techniques, while fast, suffer from an unacceptable percentage of false positives and false negatives. To complement both manual and automated analysis of network traffic, we applied information visualization techniques to appropriately and effectively bring the human into the analytic loop. This paper describes the implementation and lessons learned from the creation of a novel network traffic visualization system capable of both realtime and forensic data analysis. Combining the strength of link analysis using parallel coordinate plots with the time-sequence animation of scatter plots, we examine a 2D and 3D coordinated display that provides insight into both legitimate and malicious network activity. Our results indicate that analysts can rapidly examine network traffic and detect anomalies far more quickly than with manual tools.
Keywords
computer animation; computer networks; data analysis; data visualisation; pattern recognition; real-time systems; security of data; telecommunication security; 2D coordinated display; 3D coordinated display; analytic loop; animated visualization; anomaly detection; coordinated visualization; forensic network data analysis; honeynet visualization; honeypot visualization; information visualization; link analysis; malicious activity classification; malicious activity detection; network activity; network traffic visualization system; parallel coordinate plots; real-time network data analysis; scatter plots; security visualization; time-sequence animation; Animation; Data analysis; Data visualization; Forensics; Humans; Information analysis; Manuals; Scattering; Telecommunication traffic; Three dimensional displays;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Assurance Workshop, 2005. IAW '05. Proceedings from the Sixth Annual IEEE SMC
Print_ISBN
0-7803-9290-6
Type
conf
DOI
10.1109/IAW.2005.1495932
Filename
1495932
Link To Document