首页> 外文会议>Visualization for Computer Security >Large-Scale Network Monitoring for Visual Analysis of Attacks
【24h】

Large-Scale Network Monitoring for Visual Analysis of Attacks

机译:大规模网络监控,以可视化方式分析攻击

获取原文
获取原文并翻译 | 示例

摘要

The importance of the Internet and our dependency on computer networks are steadily growing, which results in high costs and substantial consequences in case of successful intrusions, stolen data, and interrupted services. At the same time, a trend towards massive attacks against the network infrastructure is noticeable. Therefore, monitoring large networks has become an important field in practice and research. Through monitoring systems, attacks can be detected and analyzed to gain knowledge of how to better protect the network in the future. In the scope of this paper, we present a system to analyze NetFlow data using a relational database system. NetFlow records are linked with alerts from an intrusion detection system to enable efficient exploration of suspicious activity within the monitored network. Within the system, the monitored network is mapped to a TreeMap visualization, the attackers are arranged at the borders and linked using splines parameterized with prefix information. In a series of case studies, we demonstrate how the tool can be used to judge the relevance of alerts, to reveal massive distributed attacks, and to analyze service usage within a network.
机译:Internet的重要性以及我们对计算机网络的依赖性正在稳步增长,如果成功入侵,数据被盗以及服务中断,这将导致高成本和重大后果。同时,对网络基础架构进行大规模攻击的趋势十分明显。因此,监控大型网络已成为实践和研究的重要领域。通过监视系统,可以检测和分析攻击,以获取有关如何在将来更好地保护网络的知识。在本文的范围内,我们提出一种使用关系数据库系统分析NetFlow数据的系统。 NetFlow记录与来自入侵检测系统的警报链接,以实现对受监视网络内可疑活动的有效探索。在系统内,将受监视的网络映射到TreeMap可视化文件,将攻击者布置在边界处,并使用通过前缀信息进行参数设置的样条线进行链接。在一系列案例研究中,我们演示了如何使用该工具来判断警报的相关性,揭示大规模分布式攻击以及分析网络中的服务使用情况。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号