首页> 外文会议>International Workshop on Visualization for Computer Security >Using Time Series 3D AlertGraph and False Alert Classification to Analyse Snort Alerts
【24h】

Using Time Series 3D AlertGraph and False Alert Classification to Analyse Snort Alerts

机译:使用时间序列3D Alertgraph和False Alert分类来分析Snort警报

获取原文

摘要

A top-level overview of Snort alerts using 3D visual and alert classification is discussed. This paper describes the top-level view (time series 3D AlertGraph) with the integration of alert classification to visualise Snort alerts. The advantages of using this view are (1) It summarised the alerts into different colours to indicate the quantity of alerts from (SRCIP, DPORT) pairs; (2) It used alert classification to highlight the true alerts; (3) Through interaction tools, the alerts can be highlighted according to the source IP, destination IP or destination port;. (4) A large numbers of alerts can be viewed in a single display and (5) A temporal characteristic of attacks can be discovered.
机译:讨论了使用3D视觉和警报分类的Snort警报的顶级概述。本文介绍了顶级视图(时间序列3D Alertgraph),并集成了警报分类以可视化Snort警报。使用此视图的优点是(1)总结了警报以不同的颜色,以指示来自(SRCIP,DPORT)对的警报数量; (2)它使用警报分类来突出真正的警报; (3)通过交互工具,可以根据源IP,目标IP或目标端口突出显示警报; (4)可以在单个显示中查看大量警报,并且(5)可以发现攻击的时间特征。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号