A Novel Radial Visualization of Intrusion Detection Alerts

被引:14
|
作者
Shi, Yang [1 ,2 ]
Zhao, Ying [3 ]
Zhou, Fangfang [3 ]
Shi, Ronghua [3 ]
Zhang, Yaoxue [4 ]
Wang, Guojun [5 ]
机构
[1] Cent S Univ, Changsha, Hunan, Peoples R China
[2] Tongji Univ, Intelligent Big Data Visualiat Lab, Shanghai, Peoples R China
[3] Cent S Univ, Sch Informat Sci & Engn, Changsha, Hunan, Peoples R China
[4] Cent S Univ, Dept Comp Sci, Changsha, Hunan, Peoples R China
[5] Guangzhou Univ, Guangzhou, Guangdong, Peoples R China
基金
中国国家自然科学基金;
关键词
D O I
10.1109/MCG.2018.2879067
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Intrusion detection systems (IDSs) generally produce an overwhelming amount of alerts, which are commonly plagued by issues of false positives. It is cumbersome for network administrators to manually traverse text-based alert logs in order to detect threats. In this work, we present a novel radial visualization of IDSs alerts, IDSPlanet, which helps administrators identify false positives, analyze attack patterns, and understand evolving network situations. Using a planet's geology as a metaphor for the design. IDSPlanet is composed of chrono rings, alert continents, and an interactive core. Accordingly, these components encode the temporal features of alert types, patterns of behavior in affected hosts, and correlations amongst alert types. attackers, and targets, respectively. The visualization provides an informative picture of networks' status. IDSPlanet offers different interactions and monitoring modes, which allow users to investigate in detail as well as to explore overall pattern. Two case studies and two interviews were conducted to demonstrate the usability and effectiveness of our visualization design.
引用
收藏
页码:83 / 95
页数:13
相关论文
共 50 条
  • [21] A comprehensive approach to detect unknown attacks via intrusion detection alerts
    Song, Jungsuk
    Ohba, Hayato
    Takakura, Hiroki
    Okabe, Yasuo
    Ohira, Kenji
    Kwon, Yongjin
    [J]. ADVANCES IN COMPUTER SCIENCE - ASIAN 2007: COMPUTER AND NETWORK SECURITY, PROCEEDINGS, 2007, 4846 : 247 - +
  • [22] Managing intrusion-detection alerts based on fuzzy comprehensive evaluation
    Mu, CP
    Huang, HK
    Tian, SF
    [J]. Proceedings of the 8th Joint Conference on Information Sciences, Vols 1-3, 2005, : 140 - 143
  • [23] Improving Usability and Intrusion Detection Alerts in a Home Video Surveillance System
    Jose Abasolo, Maria
    Sebastian Castaneda, Carlos
    [J]. COMPUTER SCIENCE - CACIC 2020, 2021, 1409 : 350 - 364
  • [24] A Rough Set Based Alerts Aggregation and Correlation Model for Intrusion Detection
    Zhou, Lin
    Wang, Chunping
    Jiang, Feng
    [J]. 2012 THIRD INTERNATIONAL CONFERENCE ON TELECOMMUNICATION AND INFORMATION (TEIN 2012), 2012, : 27 - 33
  • [25] Real-time analysis of intrusion detection alerts via correlation
    Lee, Soojin
    Chung, Byungchun
    Kim, Heeyoul
    Lee, Yunho
    Park, Chanil
    Yoon, Hyunsoo
    [J]. COMPUTERS & SECURITY, 2006, 25 (03) : 169 - 183
  • [26] Towards Understanding Alerts raised by Unsupervised Network Intrusion Detection Systems
    Lanvin, Maxime
    Gimenez, Pierre-Francois
    Han, Yufei
    Majorczyk, Frederic
    Me, Ludovic
    Totel, Eric
    [J]. PROCEEDINGS OF THE 26TH INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, RAID 2023, 2023, : 135 - 150
  • [27] Handling Alerts for Intrusion Detection System Using Stateful Pattern Matching
    Chakir, El Mostapha
    Idrissi Khamlichi, Youness
    Moughit, Mohamed
    [J]. 2016 4TH IEEE INTERNATIONAL COLLOQUIUM ON INFORMATION SCIENCE AND TECHNOLOGY (CIST), 2016, : 139 - 144
  • [28] An Alerts Correlation Technology for Large-Scale Network Intrusion Detection
    Yuan, Jingbo
    Ding, Shunli
    [J]. WEB INFORMATION SYSTEMS AND MINING, PT I, 2011, 6987 : 352 - +
  • [29] Alerts Clustering for Intrusion Detection Systems: Overview and Machine Learning Perspectives
    Alhakami, Wajdi
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2019, 10 (05) : 573 - 582
  • [30] Interactive visualization of fused intrusion detection data
    Avitia, Serafin
    Kurkowski, Stuart
    van der Hoeven, Luke
    [J]. 3RD INTERNATIONAL CONFERENCE ON INFORMATION WARFARE AND SECURITY, PROCEEDINGS, 2008, : 27 - 36