TY - GEN
T1 - IDGraphs
T2 - IEEE Workshop on Visualization for Computer Security 2005, VizSEC 05
AU - Ren, Pin
AU - Gao, Yan
AU - Li, Zhichun
AU - Chen, Yan
AU - Watson, Benjamin
N1 - Copyright:
Copyright 2011 Elsevier B.V., All rights reserved.
PY - 2005
Y1 - 2005
N2 - Traffic anomalies and attacks are commonplace in today's networks and identifying them rapidly and accurately is critical for large network operators. For a statistical intrusion detection system (IDS), it is crucial to detect at the flow-level for accurate detection and mitigation. However, existing IDS systems offer only limited support for 1) interactively examining detected intrusions and anomalies, 2) analyzing worm propagation patterns, 3) and discovering correlated attacks. These problems are becoming even more acute as the traffic on today's high-speed routers continues to grow. IDGraphs is an interactive visualization system for intrusion detection that addresses these challenges. The central visualization in the system is a flow-level trace plotted with time on the horizontal axis and aggregated number of unsuccessful connections on the vertical axis. We then summarize a stack of tens or hundreds of thousands of these traces using the Histographs[23] technique, which maps data frequency at each pixel to brightness. Users may then interactively query the summary view, performing analysis by highlighting subsets of the traces. For example, brushing a linked correlation matrix view highlights traces with similar patterns, revealing distributed attacks that are difficult to detect using standard statistical analysis. We apply IDGraphs system to a real network router data-set with 179M flow-level records representing a total traffic of 1.16TB. The system successfully detects and analyzes a variety of attacks and anomalies, including port scanning, worm outbreaks, stealthy TCP SYN floodings, and some distributed attacks.
AB - Traffic anomalies and attacks are commonplace in today's networks and identifying them rapidly and accurately is critical for large network operators. For a statistical intrusion detection system (IDS), it is crucial to detect at the flow-level for accurate detection and mitigation. However, existing IDS systems offer only limited support for 1) interactively examining detected intrusions and anomalies, 2) analyzing worm propagation patterns, 3) and discovering correlated attacks. These problems are becoming even more acute as the traffic on today's high-speed routers continues to grow. IDGraphs is an interactive visualization system for intrusion detection that addresses these challenges. The central visualization in the system is a flow-level trace plotted with time on the horizontal axis and aggregated number of unsuccessful connections on the vertical axis. We then summarize a stack of tens or hundreds of thousands of these traces using the Histographs[23] technique, which maps data frequency at each pixel to brightness. Users may then interactively query the summary view, performing analysis by highlighting subsets of the traces. For example, brushing a linked correlation matrix view highlights traces with similar patterns, revealing distributed attacks that are difficult to detect using standard statistical analysis. We apply IDGraphs system to a real network router data-set with 179M flow-level records representing a total traffic of 1.16TB. The system successfully detects and analyzes a variety of attacks and anomalies, including port scanning, worm outbreaks, stealthy TCP SYN floodings, and some distributed attacks.
KW - Brushing and Linking
KW - Correlation Matrix
KW - Dynamic Query
KW - Interactive System
KW - Intrusion Detection
KW - Visualization
UR - http://www.scopus.com/inward/record.url?scp=33749519234&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=33749519234&partnerID=8YFLogxK
U2 - 10.1109/VIZSEC.2005.1532064
DO - 10.1109/VIZSEC.2005.1532064
M3 - Conference contribution
AN - SCOPUS:33749519234
SN - 0780394771
SN - 9780780394773
SN - 0780394771
SN - 9780780394773
T3 - IEEE Workshop on Visualization for Computer Security 2005, VizSEC 05, Proceedings
SP - 39
EP - 46
BT - IEEE Workshop on Visualization for Computer Security 2005, VizSEC 05, Proceedings
Y2 - 26 October 2005 through 26 October 2005
ER -