DocumentCode :
2020669
Title :
IPMatrix: an effective visualization framework for cyber threat monitoring
Author :
Ohno, Kazuhiro ; Koike, Hideki ; Koizumi, Kanba
Author_Institution :
Graduate Sch. of Inf. Syst., Electro-Commun. Univ., Osaka, Japan
fYear :
2005
fDate :
6-8 July 2005
Firstpage :
678
Lastpage :
685
Abstract :
An effective Internet cyber threat monitoring system detects cyber threats using network sensors deployed at particular points on the Internet, statistically analyses the time of attack, source of attack, and type of attack, and then visualizes the result of this analysis. Existing systems, however, simply visualize country-by-country statistics of attacks or hourly changes of attacks. Using these systems, it is difficult to understand the source of attack, the diffusion of the attack, or the relation between the target and the source of the attack. This paper described a method for visualizing cyber threats by using 2-dimensional matrix representation of IP addresses. The advantages of this method are that: (I) the logical distance of IP addresses is represented intuitively, (2) Internet address space is visualized economically, (3) macroscopic information (site level) and microscopic information (local level) are visualized simultaneously. By using this visualization framework, propagation of the Welchia worm and the Sasser.D worm are visualized.
Keywords :
Internet; data visualisation; security of data; 2D matrix representation; IP address; IPMatrix; Internet address space visualization; Internet cyber threat monitoring system; Sasser.D worm; Welchia worm; country-by-country statistics; cyber threat visualization; macroscopic information visualization; microscopic information visualization; network sensor; Computer worms; Data visualization; Economic forecasting; IP networks; Information analysis; Internet; Intrusion detection; Monitoring; Sensor systems; Statistics; Internet worm; computer virus; information security; information visualization; intrusion detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Visualisation, 2005. Proceedings. Ninth International Conference on
ISSN :
1550-6037
Print_ISBN :
0-7695-2397-8
Type :
conf
DOI :
10.1109/IV.2005.67
Filename :
1509147
Link To Document :
بازگشت