• DocumentCode
    2931315
  • Title

    A Novel Visualization Approach for Efficient Network-wide Traffic Monitoring

  • Author

    Samak, Taghrid ; El-Atawy, Adel ; Al-Shaer, Ehab ; Ismail, Mohamed

  • Author_Institution
    DePaul Univ., Chicago
  • fYear
    2007
  • fDate
    Yearly 21 2007-May 21 2007
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    Network traffic visualization provides very effective means for monitoring anomalous activities as well as detecting large scale network attacks. This work proposes a novel and flexible technique for representing traffic activities that reside in network flows and their patterns. The technique utilizes a set of different space-filling curves (SFC) to map the collected statistics to images that emphasize traffic patterns. Our approach to use the enhanced locality of SFC clustering property makes anomalies such as large scale DDoS attacks and scanning activities easily identifiable, compared to other traditional techniques. Also, widely dispersed communication patterns are rendered easier to understand using our proposed traffic-to-image mappings. This new representation preserves traffic properties leading to more accurate and robust anomaly detection even if aggressive compression is performed on the resulting images. In addition, using our proposed technique, the relation between multiple packet fields can be easily obtained to analyze correlated attacks.
  • Keywords
    computer networks; data visualisation; telecommunication security; telecommunication traffic; dispersed communication patterns; enhanced locality; large scale network attacks; multiple packet fields; network traffic visualization; network-wide traffic monitoring; space-filling curves; traffic-to-image mappings; Computer crime; Computerized monitoring; Filling; Image analysis; Image coding; Large-scale systems; Performance analysis; Statistics; Telecommunication traffic; Visualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    End-to-End Monitoring Techniques and Services, 2007. E2EMON '07. Workshop on
  • Conference_Location
    Munich
  • Print_ISBN
    1-4244-1289-7
  • Type

    conf

  • DOI
    10.1109/E2EMON.2007.375319
  • Filename
    4261340