首页> 外文会议>International symposium on cyberspace safety and security >NetSecRadar: A Visualization System for Network Security Situational Awareness
【24h】

NetSecRadar: A Visualization System for Network Security Situational Awareness

机译:NetSecRadar:网络安全情况感知的可视化系统

获取原文

摘要

Situational awareness is defined as the ability to effectively determine an overall computer network status based on relationships between security events in multiple dimensions. Unfortunately, as the lack of tools to synthetically analyze the security logs generated by kinds of network security products, such as NetFlow, Firewall and Host Security, it is difficult to monitor and perceive network security situational awareness. Information visualization allows users to discover and analyze large amounts of information through visual exploration and interaction efficiently. Even with the aid of visualization, identifying the attack patterns from big multi-source data and recognizing the abnormal from visual clutter are still challenges. In this paper, a novel visualization system, NetSecRadar, is proposed for network security situational awareness based on multi-source logs, which can monitor the network and perceive the overall view of the security situation by using radial graph. NetSecRadar utilizes a hierarchical force-directed graph layout for arrangement of thousands of hosts to better use the available screen space, and provides the method to quantify the dangerous levels of the security events, and finds the correlations of security events generated by multi-source logs and perceives the patterns of abnormal in situational awareness, and synthesizes interactions, filtering and drill-down to understand the detail information. To demonstrate the system's capabilities, we utilize the VAST Challenge 2013 as case study.
机译:情境意识定义为基于多维安全事件之间的关系有效确定总体计算机网络状态的能力。不幸的是,由于缺乏用于综合分析由各种网络安全产品(例如NetFlow,防火墙和主机安全性)生成的安全日志的工具,因此难以监视和感知网络安全态势感知。信息可视化使用户可以通过可视化探索和交互来发现和分析大量信息。即使借助可视化,从大型多源数据中识别攻击模式并从视觉混乱中识别异常仍然是挑战。本文提出了一种新颖的可视化系统NetSecRadar,用于基于多源日志的网络安全态势感知,该系统可以使用径向图来监视网络并感知安全态势的整体视图。 NetSecRadar利用分层的力导向图布局来排列数千个主机,以更好地利用可用的屏幕空间,并提供了量化安全事件危险级别的方法,并找到了由多源日志生成的安全事件的相关性并感知态势感知中的异常模式,并进行交互,过滤和深入分析以了解详细信息。为了演示系统的功能,我们以VAST Challenge 2013为例。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号