NetBytes Viewer: An Entity-Based NetFlow Visualization Utility for Identifying Intrusive Behavior
نویسندگان
چکیده
NetBytes Host Viewer is an interactive visualization tool designed to show the historical network flow data per port of an individual host machine or subnet on a network over time, using a 3D impulse graph plot. Such visualizations allow network administrators to quickly and effectively diagnose infected or malfunctioning computers by viewing data transmission patterns for each port on the entity. NetBytes has a set of interactive features which help to deal with the problems associated with displaying a 3D graph on a 2D screen. First, NetBytes offers a “selector” mode which allows the user to highlight specific ports (or times) on the graph using a slider and snap buttons. From the selector, the user can launch a set of 2D graphs (Bytes vs. Time and Bytes vs. Ports) to acquire more detailed information about the host with less clutter. Lastly, the user is able to rotate the 3D graph in any direction to mitigate occlusion. The long term objectives of this work include the integration of the NetBytes Viewer with complementary visualizations of the overall network. This application will integrate with a larger network analysis tool and be utilized as a drill-down mechanism. 1
منابع مشابه
Community-based Analysis of Netflow for Early Detection of Security Incidents
Detection and remediation of security incidents (e.g., attacks, compromised machines, policy violations) is an increasingly important task of system administrators. While numerous tools and techniques are available (e.g., Snort, nmap, netflow), novel attacks and low-grade events may still be hard to detect in a timely manner. In this paper, we present a novel approach for detecting stealthy, lo...
متن کاملViewer Perception of Superellipsoid-based Accelerometer Visualization Techniques
Viewer perceptions of superellipsoid-based glyphs representing trend analysis of tri-axial accelerometer data are studied in this paper. A trend analysis and its mapping to the superellipsoid parameters is proposed. Detailed results from a viewer survey about the usefulness of such glyphs are presented. Survey results indicate that approximately 60% of the respondents correctly identified the t...
متن کاملMathIOmica‐MSViewer: a dynamic viewer for mass spectrometry files for Mathematica
MathIOmica-MSViewer is an add-on graphical user interface utility for the Mathematica software system which facilitates the visualization and exploration of spectra from open format mass spectrometry files (mzXML and mzML standard community formats). The viewer was designed for simplicity and handling of large mass spectrometry data files. To facilitate searches, users may use search filters fo...
متن کاملPassive One-Way-Delay Measurements and Data Export
This document describes a non-intrusive method for measuring one-way delay of IP packets. Furthermore it describes how to use NetFlow Version 9 to export the data of such measurements and evaluation processes.
متن کاملDiachronic Manuscript Registration and Visualization
This paper presents a software framework for the registration and visualization of layered image sets. To demonstrate the utility of these tools, we apply them to the St. Chad Gospels, relying on images of each page of the manuscript as it appeared over time. An automated registration pipeline is used to perform nonrigid registration on each series of images. To visualize the differences betwee...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2007