Title :
VAST 2012 Mini-Challenge 2: Chart- and Matrix-based approach to network operations forensics
Author :
Hildenbrand, Jan ; Paval, Daniel-Ionut ; Thapa, Prakash ; Rohrdantz, Christian ; Mansmann, Florian ; Bertini, Enrico ; Schreck, Tobias
Author_Institution :
University of Konstanz, Germany
Abstract :
We report the approach and results on the VAST 2012 MiniChallenge 2: Bank of Money Regional Office Network Operations Forensics. Using commercial data mining, visualization and database software such as KNIME, Tableau and MySQL as well as a custom-written source vs. destination IP pixel matrix, our team of students identified suspicious IRC traffic, an attack on the firewall, a drop in the firewall connections, an attempt for sensitive information exchange and a possible Distributed Denial-of-Service attack executed partly from a host within the bank network.
Conference_Titel :
Visual Analytics Science and Technology (VAST), 2012 IEEE Conference on
Conference_Location :
Seattle, WA
Print_ISBN :
978-1-4673-4752-5
DOI :
10.1109/VAST.2012.6400513