The design of VisFlowConnect-IP: a link analysis system for IP security Situational awareness

被引:0
|
作者
Yin, XX [1 ]
Yurcik, W [1 ]
Slagell, A [1 ]
机构
[1] Univ Illinois, NCSA, Urbana, IL USA
关键词
NetFlow; security situational awareness; link analysis; security visualization;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Visualization of IP-based traffic dynamics on networks is a challenging task due to large data volume and the complex, temporal relationships between hosts. We present the architecture of VsFlowConnect-IP, a powerful new tool to visualize IP network traffic flow dynamics for security situational awareness. VtsFlowConnect-IP allows an operator to visually assess the connectivity of large and complex networks on a single screen. It provides an overall view of the entire network and filter/drill-down features that allow operators to request more detailed information. Preliminary reports from several organizations using this tool report increased responsiveness to security events as well as new insights into understanding the security dynamics of their networks. In this paper we focus specifically on the design decisions made during the VsFlowConnect development process so that others may learn from our experience. The current VsFlowConnect architecture-the result of these design decisions-is extensible to processing other highvolume multi-dimensional data streams where link connectivity/activity is a focus of study. We report experimental results quantifying the scalability of the underlying algorithms for representing link analysis given continuous highvolume traffic flows as input.
引用
收藏
页码:141 / 153
页数:13
相关论文
共 50 条
  • [1] VisFlowConnect: Providing security situational awareness by visualizing network traffic flows
    Yin, XX
    Yurcik, W
    Li, YF
    Lakkaraju, K
    Abad, C
    [J]. CONFERENCE PROCEEDINGS OF THE 2004 IEEE INTERNATIONAL PERFORMANCE, COMPUTING, AND COMMUNICATIONS CONFERENCE, 2004, : 601 - 607
  • [2] Design and implementation of mobile IP system with security consideration
    Ishiyama, M
    Inoue, A
    Fukumoto, A
    Okamoto, T
    [J]. WORLDWIDE COMPUTING AND ITS APPLICATIONS - WWCA'98, 1998, 1368 : 238 - 253
  • [3] The Classification, Design and Placement of Security Sensor for Network Security Situational Awareness System
    Wang Hui-qiang
    Lai Ji-bao
    Liang Ying
    Liu Xiao-wu
    [J]. ICICSE: 2008 INTERNATIONAL CONFERENCE ON INTERNET COMPUTING IN SCIENCE AND ENGINEERING, PROCEEDINGS, 2008, : 321 - 324
  • [4] IP Storage Security Analysis
    Bilski, Tomasz
    [J]. COMPUTER NETWORKS, 2012, 291 : 216 - 228
  • [5] Design and Analysis of a Hierarchical IP Traceback System
    Dabir, Abes
    Matrawy, Ashraf
    [J]. 2009 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-8, 2009, : 971 - 976
  • [6] Security Analysis Survey and Framework Design for IP connected LoWPANs
    Riaz, Rabia
    Kim, Ki-Hyung
    Ahmed, H. Farooq
    [J]. ISADS 2009: 2009 INTERNATIONAL SYMPOSIUM ON AUTONOMOUS DECENTRALIZED SYSTEMS, PROCEEDINGS, 2009, : 29 - +
  • [7] Survivable IP Link Topology Design in an IP-over-WDM Architecture
    Choudhury, Gagan L.
    Klincewicz, John G.
    [J]. 2009 7TH INTERNATIONAL WORKSHOP ON THE DESIGN OF RELIABLE COMMUNICATION NETWORKS (DRCN 2009), 2009, : 147 - 152
  • [8] Architecture for the Cyber Security Situational Awareness System
    Kokkonen, Tero
    [J]. INTERNET OF THINGS, SMART SPACES, AND NEXT GENERATION NETWORKS AND SYSTEMS, NEW2AN 2016/USMART 2016, 2016, 9870 : 294 - 302
  • [9] Analysis of link failures in an IP backbone
    Iannaccone, G
    Chuah, CN
    Mortier, R
    Bhattacharyya, S
    Diot, C
    [J]. IMW 2002: PROCEEDINGS OF THE SECOND INTERNET MEASUREMENT WORKSHOP, 2002, : 237 - 242
  • [10] Research on a Critical Link Discovery Method for Network Security Situational Awareness
    Yang, Guozheng
    Zhang, Yongheng
    Lu, Yuliang
    Xie, Yi
    Yu, Jiayi
    [J]. ENTROPY, 2024, 26 (04)