Personal tools
You are here: Home pubs VizSec 2007 Proceedings Visualization of Host Behavior for Network Security
Document Actions

F Mansman, L Meier, and D A Keim (2008)

Visualization of Host Behavior for Network Security

In: VizSEC 2007: Proceedings of the Workshop on Visualization for Computer Security, Date-Added = 2008-06-24 09:46:43 -0400, Date-Modified = 2008-06-24 09:46:52 -0400, edited by Goodall, J. R. and Conti, G. and Ma, K. L.. Springer, pages 187-202.

Monitoring host behavior in a network is one of the most essential tasks in the fields of network monitoring and security since more and more malicious code in the wild internet constantly threatens the network infrastructure. In this paper, we present a visual analytics tool that visualizes network host behavior through positional changes in a two-dimensional space using a force-directed graph layout algorithm. The tool's interaction capabilities allow for visual exploration of network traffic over time and are demonstrated using netflow data as well as IDS alerts. Automatic accentuation of hosts with highly variable traffic results in fast hypothesis generation and confirmation of suspicious host behavior. By triggering the behavior graph from the HNMap tool, we were able to monitor more abstract network entities.
10.1007/978-3-540-78243-8_13
 
by John Goodall last modified 2008-06-24 05:50
Log in


Forgot your password?
New user?
related from amazon
Navigation
 
Sponsored by

google search
Google
advertisements
 

Powered by Plone CMS, the Open Source Content Management System

This site conforms to the following standards: