4.6 Article

A Matrix-Based Visualization System for Network Traffic Forensics

期刊

IEEE SYSTEMS JOURNAL
卷 10, 期 4, 页码 1350-1360

出版社

IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
DOI: 10.1109/JSYST.2014.2358997

关键词

Cyber security; entropy; information visualization; traffic forensics; VAST challenge

资金

  1. National Natural Science Foundation of China [61103108, 61402540, 61103096]
  2. National Science AMP
  3. Technology Pillar Program of China [2012BAH08B01]
  4. Hunan Provincial Science and Technology Program [2012RS4049]
  5. Hunan Provincial Natural Science Foundation [12JJ3062]

向作者/读者索取更多资源

Network forensics requires analysts to efficiently reason about various attack phenomena from massive data. Visualization techniques can convert abstract data into visual sensitive graphics; thus, forensic officers can extract useful information quickly. In this paper, we present a matrix-based visualization system for visualized forensic analysis on unintelligible traffic datasets. The system consists of three collaborative views, including the Timeline view integrating active features and individual dispersions based on information entropies for the perception of the overall time series, the Matrix view balancing the expression of network structure and distributions of IPs and ports for efficient events tracing, and the Historical view comparing statuses in successive time slots for dynamic trends tracking. The system provides a multilevel analysis architecture and multifaceted perspectives for comprehensive cognition in traffic forensics. In case studies, we describe the forensic process of this system, including identifying port scan, distributed denial of service, and botnet attacks, on the datasets in VAST Challenge 2013.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.6
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据