Focusing on context in network traffic analysis

被引:29
|
作者
Goodall, JR [1 ]
Lutters, WG
Rheingans, P
Komlodi, A
机构
[1] Univ Maryland Baltimore Cty, Dept Informat Syst, Baltimore, MD 21228 USA
[2] Univ Maryland Baltimore Cty, Dept Comp Sci, Baltimore, MD 21228 USA
关键词
D O I
10.1109/MCG.2006.31
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Intrusion detection analysis requires understanding the context of an event, usually discovered by examining packet-level detail. When analysts attempt to construct the big picture of a security event, they must move between high-level representations and these low-level details. This continual shifting places a substantial cognitive burden on the analyst, who must mentally store and transfer information between these levels of analysis. This article presents an information visualization tool, the time-based network traffic visualizer (TNV), which reduces this burden. TNV augments the available support for discovering and analyzing anomalous or malicious network activity. The system is grounded in an understanding of the work practices of intrusion detection analysts, particularly foregrounding the overarching importance in the analysis task of integrating contextual information into an understanding of the event under investigation. TNV provides low-level, textual data and multiple, linked visualizations that enable analysts to simultaneously examine packet-level detail within the larger context of activity. © 2006 IEEE.
引用
收藏
页码:72 / 80
页数:9
相关论文
共 50 条
  • [21] Network Traffic Classification for Security Analysis
    Boger, Mark
    Liu, Tianyuan
    Ratliff, Jacqueline
    Nick, William
    Yuan, Xiaohong
    Esterline, Albert
    SOUTHEASTCON 2016, 2016,
  • [22] Traffic Analysis of a University local Network
    Rios, Rene
    Fermin, Jose R.
    TELEMATIQUE, 2009, 8 (02): : 15 - 27
  • [23] Network Traffic Analysis with Cloud Platform
    Lin, Richard Chun-Hung
    Liao, Hung-Jen
    Tung, Kuang-Yuan
    Lin, Ying-Chih
    Wu, Shih-Lin
    JOURNAL OF INTERNET TECHNOLOGY, 2012, 13 (06): : 953 - 961
  • [24] Network traffic analysis and modeling for games
    Park, H
    Kim, T
    Kim, S
    INTERNET AND NETWORK ECONOMICS, PROCEEDINGS, 2005, 3828 : 1056 - 1065
  • [25] Analysis of nonuniform traffic in a switching network
    Mir, N
    7TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS - PROCEEDINGS, 1998, : 668 - 672
  • [26] Network Traffic Analysis Based on Hadoop
    Yang, Jie
    He, Haiyang
    Qiao, Yuanyuan
    2014 4TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, VEHICULAR TECHNOLOGY, INFORMATION THEORY AND AEROSPACE & ELECTRONIC SYSTEMS (VITAE), 2014,
  • [27] Analysis of Air Traffic Network of China
    Wang, Hongyong
    Wen, Ruiying
    PROCEEDINGS OF THE 2012 24TH CHINESE CONTROL AND DECISION CONFERENCE (CCDC), 2012, : 2400 - 2403
  • [28] A software tool for network traffic analysis
    Sun, F.
    Tzeng, H.
    SNPD 2006: SEVENTH ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING ARTIFICIAL INTELLIGENCE, NETWORKING, AND PARALLEL/DISTRIBUTED COMPUTING, PROCEEDINGS, 2006, : 190 - +
  • [29] Traffic Measurement and Analysis of a Campus Network
    Zhang, Weiyu
    INTERNATIONAL SYMPOSIUM ON SIGNAL PROCESSING BIOMEDICAL ENGINEERING, AND INFORMATICS (SPBEI 2013), 2014, : 1164 - 1172
  • [30] Network Analytics for Streaming Traffic Analysis
    Khanchi, Sara
    Zincir-Heywood, Nur
    Heywood, Malcolm
    2019 IFIP/IEEE SYMPOSIUM ON INTEGRATED NETWORK AND SERVICE MANAGEMENT (IM), 2019, : 25 - 30