IDSRadar: a real-time visualization framework for IDS alerts

被引:5
|
作者
Zhao Ying [1 ]
Zhou FangFang [1 ]
Fan XiaoPing [1 ,2 ]
Liang Xing [1 ]
Liu YongGang [1 ]
机构
[1] Cent S Univ, Informat Sci & Engn Sch, Changsha 410075, Hunan, Peoples R China
[2] Hunan Univ Finance & Econ, Lab Networked Syst, Changsha 410205, Hunan, Peoples R China
基金
中国国家自然科学基金;
关键词
visual analytics; information visualization; cyber security; IDS log; entropy; VISUAL CORRELATION; NETWORK; CLASSIFICATION;
D O I
10.1007/s11432-013-4891-9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion Detection Systems (IDS) is an automated cyber security monitoring system to sense malicious activities. Unfortunately, IDS often generates both a considerable number of alerts and false positives in IDS logs. Information visualization allows users to discover and analyze large amounts of information through visual exploration and interaction efficiently. Even with the aid of visualization, identifying the attack patterns and recognizing the false positives from a great number of alerts are still challenges. In this paper, a novel visualization framework, IDSRadar, is proposed for IDS alerts, which can monitor the network and perceive the overall view of the security situation by using radial graph in real-time. IDSRadar utilizes five categories of entropy functions to quantitatively analyze the irregular behavioral patterns, and synthesizes interactions, filtering and drill-down to detect the potential intrusions. In conclusion, IDSRadar is used to analyze the mini-challenges of the VAST challenge 2011 and 2012.
引用
收藏
页码:1 / 12
页数:12
相关论文
共 50 条
  • [11] FEX - A Feature Extractor for Real-Time IDS
    Schaad, Andreas
    Binder, Dominik
    [J]. INFORMATION SECURITY (ISC 2021), 2021, 13118 : 221 - 237
  • [12] Real-time correlation of network security alerts
    Li, Zhitang
    Zhang, Aifang
    Lei, Jie
    Wang, Li
    [J]. ICEBE 2007: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2007, : 73 - +
  • [13] Sustainable Data Collection Framework: Real-Time, Online Data Visualization
    Sun, Tien-Lung
    Salgado, Gustavo Adolfo Miranda
    [J]. SUSTAINABLE DESIGN AND MANUFACTURING 2017, 2017, 68 : 58 - 67
  • [14] Real-time visualization of clouds
    Heinzlreiter, P
    Kurka, G
    Volkert, J
    [J]. WSCG'2002 SHORT COMMUNICATION PAPERS, CONFERENCE PROCEEDINGS, 2002, : 43 - 50
  • [15] Defining Real-Time Flood Alerts with Multicriteria Analysis
    Sosnoski, A. S. K. B.
    Barros, M. T. L.
    Conde, F.
    Pion, S.
    Uemura, S.
    [J]. WORLD ENVIRONMENTAL AND WATER RESOURCES CONGRESS 2018: WATER, WASTEWATER, AND STORMWATER; URBAN WATERSHED MANAGEMENT; MUNICIPAL WATER INFRASTRUCTURE; AND DESALINATION AND WATER REUSE, 2018, : 30 - 37
  • [16] A Real-Time Remote IDS Testbed for Connected Vehicles
    Zieglmeier, Valentin
    Kacianka, Severin
    Hutzelmann, Thomas
    Pretschner, Alexander
    [J]. SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING, 2019, : 1898 - 1905
  • [17] A study on the real-time modeling capabilities of the IDS method
    Murakami, M
    Honda, N
    [J]. FUZZ-IEEE 2005: PROCEEDINGS OF THE IEEE INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS: BIGGEST LITTLE CONFERENCE IN THE WORLD, 2005, : 803 - 808
  • [18] A Real-Time Multi-Dimensional Visualization Framework For Critical And Complex Environments
    Kamaleswaran, Rishikesan
    McGregor, Carolyn
    [J]. 2014 IEEE 27TH INTERNATIONAL SYMPOSIUM ON COMPUTER-BASED MEDICAL SYSTEMS (CBMS), 2014, : 325 - 328
  • [19] Cooperative visualization framework based on video streaming and real-time vectorial information
    Bobadilla, J
    Mengual, L
    [J]. COOPERATIVE DESIGN, VISUALIZATION, AND ENGINEERING, PROCEEDINGS, 2004, 3190 : 61 - 68
  • [20] Open-source framework for data storage and visualization of real-time experiments
    Prabakar, Kumaraguru
    Wunder, Nick
    Brunhart-Lupo, Nicholas
    Pailing, Courtney
    Potter, Kristi
    Eash, Matthew
    Munch, Kristin
    [J]. 2020 IEEE KANSAS POWER AND ENERGY CONFERENCE (KPEC), 2020,