An Exploration of Geolocation and Traffic Visualisation Using Network Flows

被引:0
|
作者
Pennefather, Sean [1 ]
Irwin, Barry [1 ]
机构
[1] Rhodes Univ, Dept Comp Sci, ZA-6140 Grahamstown, South Africa
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
A network flow is a data record that represents characteristics associated with a unidirectional stream of packets transmitted between two hosts using an IP layer protocol. As a network flow only represents statistics relating to the data transferred in the stream, the effectiveness of utilizing network flows for traffic visualization to aid in cyber defense is not immediately apparent and needs further exploration. The goal of this research is to explore the use of network flows for data visualization and geolocation. A prototype system capable of collecting network flows exported using the NetFlow version 9 protocol was designed and implemented as part of this research to aid in the exploration. This prototype system processes the collected flow records and renders the geolocated results on an web based interactive map. Using conformance testing it is shown that the prototype system is capable of collecting network flows and generating geolocated flow events withing 50 milliseconds of receiving the raw flow records on the test platform. The system also provides functionality for the generation of heatmaps and tools for replaying flow events from the client browser for further visual analysis. A reporter tool has also been developed to produce monthly reports on the collected network flows.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Network Interdiction Using Adversarial Traffic Flows
    Fu, Xinzhe
    Modiano, Eytan
    [J]. IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2019), 2019, : 1765 - 1773
  • [2] A Unified Approach to Network Traffic and Network Security Visualisation
    Read, Huw
    Blyth, Andrew
    Sutherland, Iain
    [J]. 2009 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-8, 2009, : 614 - 619
  • [3] Intrusion Detection Using Clustering of Network Traffic Flows
    Bailey, Matthew
    Collins, Connor
    Sinda, Matthew
    Hu, Gongzhu
    [J]. 2017 18TH IEEE/ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING (SNDP 2017), 2017, : 615 - 620
  • [4] Using complex network theory for temporal locality in network traffic flows
    Wang, Jin-Fa
    He, Xuan
    Si, Shuai-Zong
    Zhao, Hai
    Zheng, Chunyang
    Yu, Hao
    [J]. PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2019, 524 : 722 - 736
  • [5] SIMULATION OF TRAFFIC FLOWS IN A NETWORK
    SAKAI, T
    NAGAO, M
    [J]. COMMUNICATIONS OF THE ACM, 1969, 12 (06) : 311 - &
  • [6] Cobweb: a Java']Java applet for network exploration and visualisation
    von Eichborn, Joachim
    Bourne, Philip E.
    Preissner, Robert
    [J]. BIOINFORMATICS, 2011, 27 (12) : 1725 - 1726
  • [7] Network-based exploration and visualisation of ecological data
    Raymond, Ben
    Hosie, GFaham
    [J]. ECOLOGICAL MODELLING, 2009, 220 (05) : 673 - 683
  • [8] Towards Steganography Detection Through Network Traffic Visualisation
    Mazurczyk, Wojciech
    Szczypiorski, Krzysztof
    Jankowski, Bartosz
    [J]. IV INTERNATIONAL CONGRESS ON ULTRA MODERN TELECOMMUNICATIONS AND CONTROL SYSTEMS 2012 (ICUMT), 2012, : 947 - 954
  • [9] Multi-Resolution Visualisation of Geographic Network Traffic
    Kaya, Berkay
    Balcisoy, Selim
    [J]. Augmented Reality, Virtual Reality, and Computer Graphics, Pt I, 2016, 9768 : 52 - 71
  • [10] Visualisation and exploration of scientific data using graphs
    Raymond, B
    Belbin, L
    [J]. DATA MINING: THEORY, METHODOLOGY, TECHNIQUES, AND APPLICATIONS, 2006, 3755 : 14 - 27