DocumentCode :
2858195
Title :
The design of VisFlowConnect-IP: a link analysis system for IP security situational awareness
Author :
Yin, Xiaoxin ; Yurcik, William ; Slagell, Adam
Author_Institution :
National Center for Supercomput. Applications, Illinois Univ., Urbana, IL, USA
fYear :
2005
fDate :
23-24 March 2005
Firstpage :
141
Lastpage :
153
Abstract :
Visualization of IP-based traffic dynamics on networks is a challenging task due to large data volume and the complex, temporal relationships between hosts. We present the architecture of VisFlowConnect-IP, a powerful new tool to visualize IP network traffic flow dynamics for security situational awareness. VisFlowConnect-IP allows an operator to visually assess the connectivity of large and complex networks on a single screen. It provides an overall view of the entire network and filter/drill-down features that allow operators to request more detailed information. Preliminary reports from several organizations using this tool report increased responsiveness to security events as well as new insights into understanding the security dynamics of their networks. In this paper we focus specifically on the design decisions made during the VisFlowConnect development process so that others may learn from our experience. The current VisFlowConnect architecture - the result of these design decisions - is extensible to processing other high-volume multi-dimensional data streams where link connectivity/activity is a focus of study. We report experimental results quantifying the scalability of the underlying algorithms for representing link analysis given continuous high-volume traffic flows as input.
Keywords :
IP networks; data communication; inter-computer links; security of data; telecommunication links; telecommunication security; telecommunication traffic; transport protocols; IP security situational awareness; IP-based traffic dynamics visualization; Netflow; VisFlowConnect-IP architecture; computer networks; high-volume multidimensional data stream processing; link activity; link analysis system; link connectivity; network connectivity; network security dynamics; security events; temporal relationships; Complex networks; Data security; Data visualization; Delay; IP networks; Information filtering; Information filters; Information security; Power system security; Telecommunication traffic; NetFlow; link analysis; security situational awareness; security visualization;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Assurance, 2005. Proceedings. Third IEEE International Workshop on
Print_ISBN :
0-7695-2317-X
Type :
conf
DOI :
10.1109/IWIA.2005.17
Filename :
1410709
Link To Document :
بازگشت