首页> 外文学位 >FloVis: A network security visualization framework.
【24h】

FloVis: A network security visualization framework.

机译:FloVis:网络安全可视化框架。

获取原文
获取原文并翻译 | 示例

摘要

Security analysts examine gigabytes of network data on a daily basis looking for signs of intrusive behaviour. Command-line tools such as the System for Internet-Level Knowledge (SiLK) tool suite are helpful but the volume of data makes analysis difficult. We present the FloVis Netflow Visualization Framework, an extensible visualization platform meant to compliment tools such as SiLK for network analysis. Visualization is compelling because it allows the user to view significant portions of data at once and utilize his/her high bandwidth vision and pattern matching abilities for rapid data analysis. FloVis is unique because visualizations are dynamically loaded plugins within the framework, meaning that new visualizations can be added to the system as desired. In this thesis, we discuss the general framework along with three such plugins: FlowBundle, NetBytes Viewer and the SiLK Query Tool. FlowBundle shows connections between hosts on a network using bundling and node aggregation in order to reduce occlusion; NetBytes Viewer provides detailed host volume information per port/protocol over a time period using a 3D impulse graph; and, the SiLK Query Tool is a graphical front-end to the SiLK analysis tools for viewing raw NetFlow records in a tabular form. The system supports drill down and interaction between the different visualizations so that users can see the data in various ways. In addition to describing the existing state of FloVis, the thesis also discusses case studies as well as an informal user study. Finally, a discussion of the future direction of the framework is offered.
机译:安全分析员每天检查千兆字节的网络数据,以寻找侵入行为的迹象。诸如Internet级知识系统(SiLK)工具套件之类的命令行工具很有帮助,但数据量很大,使分析变得困难。我们介绍了FloVis Netflow可视化框架,这是一个可扩展的可视化平台,旨在补充诸如SiLK等工具进行网络分析。可视化之所以引人注目,是因为它允许用户立即查看数据的重要部分,并利用他/她的高带宽视觉和模式匹配能力进行快速数据分析。 FloVis是唯一的,因为可视化是框架内动态加载的插件,这意味着可以根据需要将新的可视化添加到系统中。在本文中,我们将讨论通用框架以及三个此类插件:FlowBundle,NetBytes Viewer和SiLK查询工具。 FlowBundle使用捆绑和节点聚合来显示网络主机之间的连接,以减少阻塞。 NetBytes Viewer使用3D脉冲图在一段时间内提供每个端口/协议的详细主机卷信息。并且,SiLK查询工具是SiLK分析工具的图形前端,用于以表格形式查看原始NetFlow记录。该系统支持不同可视化之间的向下钻取和交互,以便用户可以各种方式查看数据。除了描述FloVis的现有状态外,本文还讨论了案例研究和非正式用户研究。最后,讨论了该框架的未来方向。

著录项

  • 作者

    Taylor, Teryl.;

  • 作者单位

    Dalhousie University (Canada).;

  • 授予单位 Dalhousie University (Canada).;
  • 学科 Computer Science.
  • 学位 M.C.Sc.
  • 年度 2009
  • 页码 85 p.
  • 总页数 85
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

  • 入库时间 2022-08-17 11:38:26

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号