DocumentCode :
2408806
Title :
Multiple coordinated views for network attack graphs
Author :
Noel, Steven ; Jacobs, Michael ; Kalapa, Pramod ; Jajodia, Sushil
Author_Institution :
Center for Secure Inf. Syst., George Mason Univ., Fairfax, VA, USA
fYear :
2005
fDate :
26 Oct. 2005
Firstpage :
99
Lastpage :
106
Abstract :
While efficient graph-based representations have been developed for modeling combinations of low-level network attacks, relatively little attention has been paid to effective techniques for visualizing such attack graphs. This paper describes a number of new attack graph visualization techniques, each having certain desirable properties and offering different perspectives for solving different kinds of problems. Moreover, the techniques we describe can be applied not only separately, but can also be combined into coordinated attack graph views. We apply improved visual clustering to previously described network protection domains (attack graph cliques), which reduces graph complexity and makes the overall attack flow easier to understand. We also visualize the attack graph adjacency matrix, which shows patterns of network attack while avoiding the clutter usually associated with drawing large graphs. We show how the attack graph adjacency matrix concisely conveys the impact of network configuration changes on attack graphs. We also describe a novel attack graph filtering technique based on the interactive navigation of a hierarchy of attack graph constraints. Overall, our techniques scale quadratically with the number of machines in the attack graph.
Keywords :
computational geometry; data visualisation; security of data; coordinated attack graph views; graph adjacency matrix; graph complexity; graph drawing; graph filtering; graph visualization; graph-based representation; multiple coordinated views; network attack graphs; network protection domain; Chromium; Filtering; Information security; Information systems; Intrusion detection; Jacobian matrices; Navigation; Protection; Sparse matrices; Visualization;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Visualization for Computer Security, 2005. (VizSEC 05). IEEE Workshop on
Print_ISBN :
0-7803-9477-1
Type :
conf
DOI :
10.1109/VIZSEC.2005.1532071
Filename :
1532071
Link To Document :
بازگشت