Bridging the Gap of Network Management and Anomaly Detection through Interactive Visualization

Pacific Visualization Symposium(2014)

引用 26|浏览0
暂无评分
摘要
Large-scale networks have become increasingly challenging to manage. It is vital for a system administrator or network manager to be able to analyze the vast amount of log data in order to detect suspicious behaviors or patterns, possibly due to malicious users/applications or faulty devices. While an intrusion detection system (IDS) log can provide a large number of warnings, exactly which alarms are true while the others are false, and more importantly what are the underlying causes are still difficult to know. To bridge the gap between network log and anomaly discovery, we design and implement a visualization tool that combines multiple commodity visualizations with minimum learning curve. While each individual view is well understood, the effects of such views in analyzing network anomalies are not well studied. Since each visualization technique has advantages as well as limitations in addressing a particular task, we show that these views, when combined and linked together, may provide an effective and lightweight network anomaly analysis tool. The web-based open platform may simplify network administration as well as promote collaborative analysis among researchers.
更多
查看译文
关键词
lightweight network anomaly analysis,intrusion detection system log,suspicious behavior detection,ids log,malicious users,anomaly discovery,network log,network anomaly,intrusion detection system,network anomaly analysis tool,multiple commodity visualizations,computer network management,network administration,log data analysis,data analysis,computer network security,minimum learning curve,network management,anomaly detection,log data,interactive visualization,network anomaly visualization,network manager,collaborative analysis,data visualisation,internet,large-scale networks,malicious applications,web-based open platform,suspicious pattern detection,large-scale network,faulty devices,visualization,data visualization,market research,security,servers
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要