Real-time visualization of network behaviors for situational awareness.

VizSec '10: Proceedings of the Seventh International Symposium on Visualization for Cyber Security(2010)

引用 43|浏览2
暂无评分
摘要
Plentiful, complex, and dynamic data make understanding the state of an enterprise network difficult. Although visualization can help analysts understand baseline behaviors in network traffic and identify off-normal events, visual analysis systems often do not scale well to operational data volumes (in the hundreds of millions to billions of transactions per day) nor to analysis of emergent trends in real-time data. We present a system that combines multiple, complementary visualization techniques coupled with in-stream analytics, behavioral modeling of network actors, and a high-throughput processing platform called MeDICi. This system provides situational understanding of real-time network activity to help analysts take proactive response steps. We have developed these techniques using requirements gathered from the government users for which the tools are being developed. By linking multiple visualization tools to a streaming analytic pipeline, and designing each tool to support a particular kind of analysis (from high-level awareness to detailed investigation), analysts can understand the behavior of a network across multiple levels of abstraction.
更多
查看译文
关键词
real-time visualization,multiple level,network traffic,enterprise network,dynamic data,network behavior,complementary visualization technique,visualization,network actor,network flow,symbolic aggregate approximation,behavior modeling,operational data volume,real-time data,real-time,high-throughput,multiple visualization tool,real-time network activity,situational awareness,security,situation awareness,real time systems,modeling,flow,visual analysis,computer networks,real time data,high throughput,network,behavior,real time,computer graphics
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要