Focusing on context in network traffic analysis

被引:29
|
作者
Goodall, JR [1 ]
Lutters, WG
Rheingans, P
Komlodi, A
机构
[1] Univ Maryland Baltimore Cty, Dept Informat Syst, Baltimore, MD 21228 USA
[2] Univ Maryland Baltimore Cty, Dept Comp Sci, Baltimore, MD 21228 USA
关键词
D O I
10.1109/MCG.2006.31
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Intrusion detection analysis requires understanding the context of an event, usually discovered by examining packet-level detail. When analysts attempt to construct the big picture of a security event, they must move between high-level representations and these low-level details. This continual shifting places a substantial cognitive burden on the analyst, who must mentally store and transfer information between these levels of analysis. This article presents an information visualization tool, the time-based network traffic visualizer (TNV), which reduces this burden. TNV augments the available support for discovering and analyzing anomalous or malicious network activity. The system is grounded in an understanding of the work practices of intrusion detection analysts, particularly foregrounding the overarching importance in the analysis task of integrating contextual information into an understanding of the event under investigation. TNV provides low-level, textual data and multiple, linked visualizations that enable analysts to simultaneously examine packet-level detail within the larger context of activity. © 2006 IEEE.
引用
收藏
页码:72 / 80
页数:9
相关论文
共 50 条
  • [1] A multiprocessor architecture for passive analysis of network traffic focusing on complex QoS strategies
    Ferro, A
    Delgado, I
    Muñoz, A
    Liberal, F
    ICC 2005: IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-5, 2005, : 352 - 356
  • [2] Understanding the Context of Network Traffic Alerts
    Cappers, Bram C. M.
    van Wijk, Jarke J.
    2016 IEEE SYMPOSIUM ON VISUALIZATION FOR CYBER SECURITY (VIZSEC), 2016,
  • [3] WiFi concierge at home network focusing on streaming traffic
    Nishimaki, Satoru
    Yamamoto, Hiroshi
    Yamazaki, Katsuyuki
    IEICE COMMUNICATIONS EXPRESS, 2015, 4 (02): : 67 - 72
  • [4] Optimal traffic routing in the network virtualization context
    El Amri, Achref
    Meddeb, Aref
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2021, 34 (11)
  • [5] FOCUSING TECHNIQUE FOR SMALL AREA TRAFFIC ANALYSIS
    VOIGT, KH
    TRAFFIC ENGINEERING, 1977, 47 (01): : 25 - 29
  • [6] Context-Aware Behavioral Fingerprinting of IoT Devices via Network Traffic Analysis
    Prasad, Arjun
    Biju, Kevin Kanichery
    Somani, Soumya
    Mitra, Barsha
    PROCEEDINGS OF THE 20TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, SECRYPT 2023, 2023, : 335 - 344
  • [7] Context Knowledge Extraction using Network Traffic Information
    Aguilar, Jose
    Jerez, Marxjhony
    Pinto, Angel
    Gutierrez de Mesa, Jose
    Montoya, Edwin
    2022 XVLIII LATIN AMERICAN COMPUTER CONFERENCE (CLEI 2022), 2022,
  • [8] LIBSPECTOR: Context-Aware Large-Scale Network Traffic Analysis of Android Applications
    Zungur, Onur
    Stringhini, Gianluca
    Egele, Manuel
    2020 50TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN 2020), 2020, : 318 - 330
  • [9] NETWORK TRAFFIC MEASUREMENT AND ANALYSIS
    Mistry, Devang
    Modi, Prasad
    Deokule, Kaustubh
    Patel, Aditi
    Patki, Harshagandha
    Abuzaghleh, Omar
    2016 IEEE LONG ISLAND SYSTEMS, APPLICATIONS AND TECHNOLOGY CONFERENCE (LISAT), 2016,
  • [10] Vectors and Network Traffic Analysis
    Shin, Seon-Ho
    Yoon, MyungKeun
    IEEE NETWORK, 2012, 26 (01): : 22 - 26