首页> 外文学位 >Uri's Netflow Traffic Logs' Behavioral Analysis and Monitoring Visualization Tool
【24h】

Uri's Netflow Traffic Logs' Behavioral Analysis and Monitoring Visualization Tool

机译:Uri的Netflow交通日志的行为分析和监控可视化工具

获取原文
获取原文并翻译 | 示例

摘要

As long as the Internet users and the dependency of human on IT are evolving, the detailed inspection of NetFlow data will be useful, especially for the detection of cyber anomalies and outbreaks. To date, numerous researchers have examined NetFlow with respect to numerical fields including, for example, Packets, IPs, Bytes, and Bandwidth consumption. But only a handful of projects have paid attention to the analysis of NetFlow activity using categorical fields including Internet application and computer location, especially concerning a particular academic institution. The primary focus of this project is on the development of a tool for analyzing NetFlow activity at the University of Rhode Island (URI) computer network. This tool helps to monitor the NetFlow activity over time stratified first by the Primary and then by the Secondary fields selected by the user. NetFlow activity is evaluated and visualized with; frequency of traffic flow -- if user only selects filter option 'Primary Log Field', and relative frequency of traffic flow -- after selecting Field value of interest from 'Primary Log Field' if user continues and select filter option 'Secondary Log Field'. Automatically, the drill-down of data through those log fields along timestamp of interest will trigger the generation of an advanced log table grid view. Additionally, the proposed tool takes advantage of the network theory and provides visualization of the bipartite graph representation of NetFlow data subset with selected fields and time period with pre-specified sets of node degrees. This representation helps to monitor and characterize communication behavior of individual nodes in the selected time period. Overall, the tool created for this project can be regarded as the first step in the development of the comprehensive cyber security system for monitoring and analysis of the URI NetFlow activity.
机译:只要Internet用户和人们对IT的依赖性在不断发展,对NetFlow数据进行详细检查将非常有用,特别是对于检测网络异常和爆发。迄今为止,许多研究人员已经对NetFlow的数值字段进行了检查,例如包括数据包,IP,字节和带宽消耗。但是,只有少数几个项目使用Internet应用程序和计算机位置等类别字段来关注NetFlow活动的分析,尤其是有关特定学术机构的分析。该项目的主要重点是在罗德岛大学(URI)大学计算机网络上开发一种用于分析NetFlow活动的工具。该工具有助于监视NetFlow在一段时间内的活动,该活动首先由主要字段,然后由用户选择的次要字段分层。通过评估和可视化NetFlow活动;交通流量的频率-如果用户仅选择过滤器选项'Primary Log Field'和相对交通流量-在用户从'Primary Log Field'中选择了感兴趣的字段值之后,如果用户继续并选择过滤器选项'Secondary Log Field' 。自动地,沿着感兴趣的时间戳通过这些日志字段进行的数据挖掘将触发高级日志表网格视图的生成。另外,所提出的工具利用了网络理论的优势,并提供了NetFlow数据子集的二部图表示形式的可视化,其中包括选定字段和时间段以及预先指定的节点度集。此表示有助于监视和表征选定时间段内各个节点的通信行为。总体而言,为该项目创建的工具可视为开发用于监视和分析URI NetFlow活动的综合网络安全系统的第一步。

著录项

  • 作者单位

    University of Rhode Island.;

  • 授予单位 University of Rhode Island.;
  • 学科 Computer science.;Statistics.
  • 学位 M.S.
  • 年度 2018
  • 页码 86 p.
  • 总页数 86
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号