Nalazite se na CroRIS probnoj okolini. Ovdje evidentirani podaci neće biti pohranjeni u Informacijskom sustavu znanosti RH. Ako je ovo greška, CroRIS produkcijskoj okolini moguće je pristupi putem poveznice www.croris.hr
izvor podataka: crosbi !

A Visualization Framework for Traffic Data Exploration and Scan Detection (CROSBI ID 668343)

Prilog sa skupa u zborniku | izvorni znanstveni rad | međunarodna recenzija

El-Shehaly, Mai ; Gracanin, Denis ; Abdel-Hamid, Ayman ; Matkovic, Kresimir A Visualization Framework for Traffic Data Exploration and Scan Detection // 3rd International Conference on New Technologies, Mobility and Security. Institute of Electrical and Electronics Engineers (IEEE), 2009. str. 1-6 doi: 10.1109/ntms.2009.5384681

Podaci o odgovornosti

El-Shehaly, Mai ; Gracanin, Denis ; Abdel-Hamid, Ayman ; Matkovic, Kresimir

engleski

A Visualization Framework for Traffic Data Exploration and Scan Detection

Network packet traces, despite having a lot of noise, contain priceless information, especially for investigating security incidents. However, given the gigabytes of flow crossing a typical medium sized enterprise network every day, spotting malicious activity and analyzing trends in network behavior becomes a tedious task. Computational mechanisms for analyzing such data usually take substantial time to detect interesting patterns and often mislead the analyst into reaching false positives or false negatives. Therefore, the appropriate representation of network traffic data to the human user has been an issue of concern. Much of the focus, however, has been on visualizing TCP traffic alone while adapting visualization techniques for the fields that are relevant to this protocol's traffic, rather than on the multivariate nature of network security data, in general, and the fact that forensic analysis, in order to be fast and effective, has to take into consideration different parameters for each protocol. In this paper, we bring together two powerful tools: SiLK (system for Internet-level knowledge), for command-based network trace analysis ; and ComVis, a generic information visualization tool. We integrate the powers of both tools by aiding simplified interaction between them, using a simple GUI, for the purpose of visualizing network traces, characterizing interesting patterns, and fingerprinting related activity. We applied the visualizations on anonymized packet traces from Lawrence Berkley National Laboratory, captured on selected hours across three months. We used a sliding window approach in visually examining traces for two transport-layer protocols: ICMP and UDP. The main contribution of this research is a protocol-specific framework of visualization for ICMP and UDP traffic data.

visualization for ICMP and UDP traffic data

nije evidentirano

nije evidentirano

nije evidentirano

nije evidentirano

nije evidentirano

nije evidentirano

Podaci o prilogu

1-6.

2009.

objavljeno

10.1109/ntms.2009.5384681

Podaci o matičnoj publikaciji

3rd International Conference on New Technologies, Mobility and Security

Institute of Electrical and Electronics Engineers (IEEE)

978-1-4244-6273-5

Podaci o skupu

3rd International Conference on New Technologies, Mobility and Security

predavanje

20.12.2009-23.12.2009

Kairo, Egipat

Povezanost rada

Računarstvo

Poveznice