Title :
Real-time and forensic network data analysis using animated and coordinated visualization
Author :
Krasser, Sven ; Conti, Gregory ; Grizzard, Julian ; Gribschaw, Jeff ; Owen, Henry
Author_Institution :
Sch. of Electr. & Comput. Eng., eorgia Inst. of Technol., Atlanta, GA, USA
Abstract :
Rapidly detecting and classifying malicious activity contained within network traffic is a challenging problem exacerbated by large datasets and functionally limited manual analysis tools. Even on a small network, manual analysis of network traffic is inefficient and extremely time consuming. Current machine processing techniques, while fast, suffer from an unacceptable percentage of false positives and false negatives. To complement both manual and automated analysis of network traffic, we applied information visualization techniques to appropriately and effectively bring the human into the analytic loop. This paper describes the implementation and lessons learned from the creation of a novel network traffic visualization system capable of both realtime and forensic data analysis. Combining the strength of link analysis using parallel coordinate plots with the time-sequence animation of scatter plots, we examine a 2D and 3D coordinated display that provides insight into both legitimate and malicious network activity. Our results indicate that analysts can rapidly examine network traffic and detect anomalies far more quickly than with manual tools.
Keywords :
computer animation; computer networks; data analysis; data visualisation; pattern recognition; real-time systems; security of data; telecommunication security; 2D coordinated display; 3D coordinated display; analytic loop; animated visualization; anomaly detection; coordinated visualization; forensic network data analysis; honeynet visualization; honeypot visualization; information visualization; link analysis; malicious activity classification; malicious activity detection; network activity; network traffic visualization system; parallel coordinate plots; real-time network data analysis; scatter plots; security visualization; time-sequence animation; Animation; Data analysis; Data visualization; Forensics; Humans; Information analysis; Manuals; Scattering; Telecommunication traffic; Three dimensional displays;
Conference_Titel :
Information Assurance Workshop, 2005. IAW '05. Proceedings from the Sixth Annual IEEE SMC
Print_ISBN :
0-7803-9290-6
DOI :
10.1109/IAW.2005.1495932