VisFlowConnect: Providing security situational awareness by visualizing network traffic flows

被引:0
|
作者
Yin, XX [1 ]
Yurcik, W [1 ]
Li, YF [1 ]
Lakkaraju, K [1 ]
Abad, C [1 ]
机构
[1] Univ Illinois, NCSA, Urbana, IL 61801 USA
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We present the design and implementation of VisFlowConnect, a powerful new tool for visualizing network traffic flow dynamics for situational awareness. The visualization capability provided by VisFlowConnect allows an operator to assess the state of a large and complex network given an overall view of the entire network and filter/drill-down features with a friendly user interface that allows users to request more detailed information of interest such as specific protocol traffic flows. The value of VisFlowConnect specifically for security situational awareness is that any security event, with only a few minor exceptions, will be reflected as a traffic flow. Thus using VisFlowConnect a user will "see" all security events. We show several experiments in which abnormal behaviors with security implications have been discovered and analyzed using VisFlowConnect. These experiments demonstrate how VisFlowConnect can be a uniquely effective tool to assist security administrators in securing their computer networks.
引用
收藏
页码:601 / 607
页数:7
相关论文
共 50 条
  • [1] The design of VisFlowConnect-IP: a link analysis system for IP security Situational awareness
    Yin, XX
    Yurcik, W
    Slagell, A
    [J]. Third IEEE International Workshop on Information Assurance, Proceedings, 2005, : 141 - 153
  • [2] Situational awareness and network traffic analysis
    McHugh, J
    Gates, C
    Becknel, D
    [J]. Cyberspace Security and Defense: Research Issues, 2005, 196 : 209 - 228
  • [3] Survey of Network Security Situational Awareness
    Yao, Jiayu
    Fan, Xiani
    Cao, Ning
    [J]. CYBERSPACE SAFETY AND SECURITY, PT I, 2020, 11982 : 34 - 44
  • [4] Situational Awareness Technology in Network Security
    Ye, Zheng-wang
    [J]. 2014 2ND INTERNATIONAL CONFERENCE ON SOCIAL SCIENCE AND HEALTH (ICSSH 2014), PT 4, 2014, 58 : 247 - 251
  • [5] An Extraction Method Of Situational Factors For Network Security Situational Awareness
    Wang, Huiqiang
    Liang, Ying
    Ye, Haizhi
    [J]. ICICSE: 2008 INTERNATIONAL CONFERENCE ON INTERNET COMPUTING IN SCIENCE AND ENGINEERING, PROCEEDINGS, 2008, : 317 - 320
  • [6] Sonification of network traffic flow for monitoring and situational awareness
    Debashi, Mohamed
    Vickers, Paul
    [J]. PLOS ONE, 2018, 13 (04):
  • [7] Functional Requirements of Situational Awareness in Computer Network Security
    Onwubiko, Cyril
    [J]. ISI: 2009 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS, 2009, : 209 - 213
  • [8] A Study of Network Security Situational Awareness in Internet of Things
    Li, Jingyi
    Yi, Xiaoyin
    Wei, Shi
    [J]. 2020 16TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE, IWCMC, 2020, : 1624 - 1629
  • [9] Selection and Fusion of Indicators for Network Security Situational Awareness
    Fu Yanming
    Chen Pan
    Zhong Mi
    Chen Wen
    [J]. MATERIALS SCIENCE AND ENGINEERING, PTS 1-2, 2011, 179-180 : 613 - +
  • [10] Providing Information on the Spot: Using Augmented Reality for Situational Awareness in the Security Domain
    Lukosch, Stephan
    Lukosch, Heide
    Datcu, Dragos
    Cidota, Marina
    [J]. COMPUTER SUPPORTED COOPERATIVE WORK-THE JOURNAL OF COLLABORATIVE COMPUTING AND WORK PRACTICES, 2015, 24 (06): : 613 - 664