IDSRadar: a real-time visualization framework for IDS alerts

被引:5
|
作者
Zhao Ying [1 ]
Zhou FangFang [1 ]
Fan XiaoPing [1 ,2 ]
Liang Xing [1 ]
Liu YongGang [1 ]
机构
[1] Cent S Univ, Informat Sci & Engn Sch, Changsha 410075, Hunan, Peoples R China
[2] Hunan Univ Finance & Econ, Lab Networked Syst, Changsha 410205, Hunan, Peoples R China
基金
中国国家自然科学基金;
关键词
visual analytics; information visualization; cyber security; IDS log; entropy; VISUAL CORRELATION; NETWORK; CLASSIFICATION;
D O I
10.1007/s11432-013-4891-9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion Detection Systems (IDS) is an automated cyber security monitoring system to sense malicious activities. Unfortunately, IDS often generates both a considerable number of alerts and false positives in IDS logs. Information visualization allows users to discover and analyze large amounts of information through visual exploration and interaction efficiently. Even with the aid of visualization, identifying the attack patterns and recognizing the false positives from a great number of alerts are still challenges. In this paper, a novel visualization framework, IDSRadar, is proposed for IDS alerts, which can monitor the network and perceive the overall view of the security situation by using radial graph in real-time. IDSRadar utilizes five categories of entropy functions to quantitatively analyze the irregular behavioral patterns, and synthesizes interactions, filtering and drill-down to detect the potential intrusions. In conclusion, IDSRadar is used to analyze the mini-challenges of the VAST challenge 2011 and 2012.
引用
收藏
页码:1 / 12
页数:12
相关论文
共 50 条
  • [1] IDSRadar: a real-time visualization framework for IDS alerts
    Ying Zhao
    FangFang Zhou
    XiaoPing Fan
    Xing Liang
    YongGang Liu
    [J]. Science China Information Sciences, 2013, 56 : 1 - 12
  • [2] IDSRadar:a real-time visualization framework for IDS alerts
    ZHAO Ying
    ZHOU FangFang
    FAN XiaoPing
    LIANG Xing
    LIU YongGang
    [J]. Science China(Information Sciences), 2013, 56 (08) : 216 - 227
  • [3] REAL-TIME CLASSIFICATION OF IDS ALERTS WITH DATA MINING TECHNIQUES
    Vaarandi, Risto
    [J]. MILCOM 2009 - 2009 IEEE MILITARY COMMUNICATIONS CONFERENCE, VOLS 1-4, 2009, : 1786 - 1792
  • [4] AIDA Framework: Real-Time Correlation and Prediction of Intrusion Detection Alerts
    Husak, Martin
    Kaspar, Jaroslav
    [J]. 14TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2019), 2019,
  • [5] A Real-Time Visualization Defense Framework for DDoS Attack
    Jin, Yiqiao
    Liang, Qidi
    Zhang, Jian
    Jin, Ou
    [J]. DATA SCIENCE, PT 1, 2017, 727 : 341 - 351
  • [6] A Real-Time Twitter Trend Analysis and Visualization Framework
    Murthy, Jamuna S.
    Siddesh, G. M.
    Srinivasa, K. G.
    [J]. INTERNATIONAL JOURNAL ON SEMANTIC WEB AND INFORMATION SYSTEMS, 2019, 15 (02) : 1 - 21
  • [7] A Distributed Framework for Real-Time Twitter Sentiment Analysis and Visualization
    Murthy, Jamuna S.
    Siddesh, G. M.
    Srinivasa, K. G.
    [J]. RECENT FINDINGS IN INTELLIGENT COMPUTING TECHNIQUES, VOL 3, 2018, 709 : 55 - 61
  • [8] TwitSenti: A Real-Time Twitter Sentiment Analysis and Visualization Framework
    Murthy, Jamuna S.
    Siddesh, G. M.
    Srinivasa, K. G.
    [J]. JOURNAL OF INFORMATION & KNOWLEDGE MANAGEMENT, 2019, 18 (02)
  • [9] Real-Time Tracking IDs and Joints of Users
    Baek, Seongmin
    Kim, Myunggyu
    [J]. PROCEEDINGS OF 2018 VII INTERNATIONAL CONFERENCE ON NETWORK, COMMUNICATION AND COMPUTING (ICNCC 2018), 2018, : 221 - 226
  • [10] Real-Time IDS Using Reinforcement Learning
    Sagha, Hesam
    Shouraki, Saeed Bagheri
    Khasteh, Hosein
    Dehghani, Mahdi
    [J]. 2008 INTERNATIONAL SYMPOSIUM ON INTELLIGENT INFORMATION TECHNOLOGY APPLICATION, VOL II, PROCEEDINGS, 2008, : 593 - +