返回
A Matrix-Based Visualization System for Network Traffic Forensics
DOI:10.1109/JSYST.2014.2358997.png)
摘要
En 中文
Network forensics requires analysts to efficiently reason about various attack phenomena from massive data. Visualization techniques can convert abstract data into visual sensitive graphics; thus, forensic officers can extract useful information quickly. In this paper, we present a matrix-based visualization system for visualized forensic analysis on unintelligible traffic datasets. The system consists of three collaborative views, including the Timeline view integrating active features and individual dispersions based on information entropies for the perception of the overall time series, the Matrix view balancing the expression of network structure and distributions of IPs and ports for efficient events tracing, and the Historical view comparing statuses in successive time slots for dynamic trends tracking. The system provides a multilevel analysis architecture and multifaceted perspectives for comprehensive cognition in traffic forensics. In case studies, we describe the forensic process of this system, including identifying port scan, distributed denial of service, and botnet attacks, on the datasets in VAST Challenge 2013.
Keyword:
Cyber security
entropy
information visualization
traffic forensics
VAST challenge
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
I
IF:
2.4
论文数:
4.5K
被引数:
387
机构
引用论文
Sensitised near infrared emission from lanthanides via anion-templated assembly of d–f heteronuclear [2]pseudorotaxanes
New J. Chem.
IF0
INSIGHTS ON THE LIVING KIDNEY DONOR EVALUATION: LIFESTYLE HABITS AND PATIENT EXPERIENCE对活体肾捐献者评估的见解:生活方式习惯与患者体验
HEMODIALYSIS PATIENTS USING INTEGRATED PHARMACY SERVICES AT A LARGE DIALYSIS ORGANIZATION HAVE IMPROVED CLINICAL OUTCOMES在大型透析机构中使用综合药房服务的血液透析患者临床结局得到改善

