NetBytes Viewer: An Entity-Based NetFlow Visualization Utility for Identifying Intrusive Behavior

نویسندگان

  • Teryl Taylor
  • Stephen Brooks
  • John McHugh
چکیده

NetBytes Host Viewer is an interactive visualization tool designed to show the historical network flow data per port of an individual host machine or subnet on a network over time, using a 3D impulse graph plot. Such visualizations allow network administrators to quickly and effectively diagnose infected or malfunctioning computers by viewing data transmission patterns for each port on the entity. NetBytes has a set of interactive features which help to deal with the problems associated with displaying a 3D graph on a 2D screen. First, NetBytes offers a “selector” mode which allows the user to highlight specific ports (or times) on the graph using a slider and snap buttons. From the selector, the user can launch a set of 2D graphs (Bytes vs. Time and Bytes vs. Ports) to acquire more detailed information about the host with less clutter. Lastly, the user is able to rotate the 3D graph in any direction to mitigate occlusion. The long term objectives of this work include the integration of the NetBytes Viewer with complementary visualizations of the overall network. This application will integrate with a larger network analysis tool and be utilized as a drill-down mechanism. 1

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Community-based Analysis of Netflow for Early Detection of Security Incidents

Detection and remediation of security incidents (e.g., attacks, compromised machines, policy violations) is an increasingly important task of system administrators. While numerous tools and techniques are available (e.g., Snort, nmap, netflow), novel attacks and low-grade events may still be hard to detect in a timely manner. In this paper, we present a novel approach for detecting stealthy, lo...

متن کامل

Viewer Perception of Superellipsoid-based Accelerometer Visualization Techniques

Viewer perceptions of superellipsoid-based glyphs representing trend analysis of tri-axial accelerometer data are studied in this paper. A trend analysis and its mapping to the superellipsoid parameters is proposed. Detailed results from a viewer survey about the usefulness of such glyphs are presented. Survey results indicate that approximately 60% of the respondents correctly identified the t...

متن کامل

MathIOmica‐MSViewer: a dynamic viewer for mass spectrometry files for Mathematica

MathIOmica-MSViewer is an add-on graphical user interface utility for the Mathematica software system which facilitates the visualization and exploration of spectra from open format mass spectrometry files (mzXML and mzML standard community formats). The viewer was designed for simplicity and handling of large mass spectrometry data files. To facilitate searches, users may use search filters fo...

متن کامل

Passive One-Way-Delay Measurements and Data Export

This document describes a non-intrusive method for measuring one-way delay of IP packets. Furthermore it describes how to use NetFlow Version 9 to export the data of such measurements and evaluation processes.

متن کامل

Diachronic Manuscript Registration and Visualization

This paper presents a software framework for the registration and visualization of layered image sets. To demonstrate the utility of these tools, we apply them to the St. Chad Gospels, relying on images of each page of the manuscript as it appeared over time. An automated registration pipeline is used to perform nonrigid registration on each series of images. To visualize the differences betwee...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2007