Personal tools
You are here: Home applications FlowTag
Document Actions

FlowTag

Images
FlowTag FlowTag
FlowTag allows the visualization and tagging of packet flows

Current tools for forensic analysis require many hours to understand novel attacks, causing reports to be terse and untimely. We apply visual filtering and tagging of flows in a novel way to address the current limitations of post-attack analysis, reporting, and sharing. We discuss the benefits of visual filtering and tagging of network flows and introduce FlowTag as our prototype tool for the Honeynet researchers. We argue that online collaborative analysis benefits security researchers by organizing attacks, collaborating on analysis, forming attack databases for trend analysis, and in promoting new security research areas. Lastly, we show three attacks on the Georgia Tech Honeynet and describe the analysis process using FlowTag.

Links
by John Goodall last modified 2008-01-29 05:30
Sponsored by

google search
Google
advertisements
 

Powered by Plone CMS, the Open Source Content Management System

This site conforms to the following standards: