• DocumentCode
    2408640
  • Title

    A visualization methodology for characterization of network scans

  • Author

    Muelder, Chris ; Ma, Kwan-Liu ; Bartoletti, Tony

  • Author_Institution
    California Univ. Davis, USA
  • fYear
    2005
  • fDate
    26 Oct. 2005
  • Firstpage
    29
  • Lastpage
    38
  • Abstract
    Many methods have been developed for monitoring network traffic, both using visualization and statistics. Most of these methods focus on the detection of suspicious or malicious activities. But what they often fail to do refine and exercise measures that contribute to the characterization of such activities and their sources, once they are detected. In particular, many tools exist that detect network scans or visualize them at a high level, but not very many tools exist that are capable of categorizing and analyzing network scans. This paper presents a means of facilitating the process of characterization by using visualization and statistics techniques to analyze the patterns found in the timing of network scans through a method of continuous improvement in measures that serve to separate the components of interest in the characterization so the user can control separately for the effects of attack tool employed, performance characteristics of the attack platform, and the effects of network routing in the arrival patterns of hostile probes. The end result is a system that allows large numbers of network scans to be rapidly compared and subsequently identified.
  • Keywords
    data visualisation; security of data; statistical analysis; telecommunication security; adversary characterization; cyber forensics; graph visualization; information visualization; malicious activity detection; network routing; network scan analysis; network scan categorization; network scan characterization; network traffic monitoring; security visualization; statistics technique; suspicious activity detection; Condition monitoring; Continuous improvement; Pattern analysis; Performance analysis; Routing; Statistical analysis; Statistics; Telecommunication traffic; Timing; Visualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Visualization for Computer Security, 2005. (VizSEC 05). IEEE Workshop on
  • Print_ISBN
    0-7803-9477-1
  • Type

    conf

  • DOI
    10.1109/VIZSEC.2005.1532063
  • Filename
    1532063