Visual correlation of network alerts

作者: S. Foresti , J. Agutter , Y. Livnat , S. Moon , R. Erbacher

DOI: 10.1109/MCG.2006.49

关键词: VisualizationVisual analyticsNetwork securityData visualizationNetwork monitoringSoftwareComputer scienceComputer graphicsScalabilityWorld Wide WebSituation awarenessHuman–computer interactionUser-centered design

摘要: The VisAlert visual correlation tool facilitates situational awareness in complex network environments by providing a holistic view of security to help detect malicious activities. Information visualization techniques and methods many applications have effectively increased operators' awareness, letting them more detect, diagnose, treat anomalous conditions. Visualization elevates information comprehension fostering rapid perceived associations. Our technique integrates the log alert files into an intuitive, flexible, extensible, scalable - that presents critical concerning activity integrated manner, increasing user's awareness.

参考文章(16)
David E. Monarchi, Gretchen I. Puhr, A research topology for object-oriented analysis and design Communications of the ACM. ,vol. 35, pp. 35- 47 ,(1992) , 10.1145/130994.130995
Jonathan McPherson, Kwan-Liu Ma, Paul Krystosk, Tony Bartoletti, Marvin Christensen, PortVis: a tool for port-based detection of security events visualization for computer security. pp. 73- 81 ,(2004) , 10.1145/1029208.1029220
Xiaoxin Yin, William Yurcik, Michael Treaster, Yifan Li, Kiran Lakkaraju, VisFlowConnect: netflow visualizations of link relationships for security situational awareness visualization for computer security. pp. 26- 34 ,(2004) , 10.1145/1029208.1029214
Rubén Prieto-Díaz, Domain analysis ACM SIGSOFT Software Engineering Notes. ,vol. 15, pp. 47- 54 ,(1990) , 10.1145/382296.382703
Anne Treisman, Preattentive processing in vision Graphical Models \/graphical Models and Image Processing \/computer Vision, Graphics, and Image Processing. ,vol. 31, pp. 156- 177 ,(1985) , 10.1016/S0734-189X(85)80004-9
K.J. Vicente, K. Christoffersen, A. Pereklita, Supporting operator problem solving through ecological interface design systems man and cybernetics. ,vol. 25, pp. 529- 545 ,(1995) , 10.1109/21.370186
James Agutter, Frank Drews, Noah Syroid, Dwayne Westneskow, Rob Albert, David Strayer, Julio Bermudez, Matthew B. Weinger, Evaluation of graphic cardiovascular display in a high-fidelity simulator. Anesthesia & Analgesia. ,vol. 97, pp. 1403- 1413 ,(2003) , 10.1213/01.ANE.0000085298.03143.CD
Soon Tee Teoh, Kwan Liu Ma, Xiaoliang Zhao, S. Felix Wu, Case study: Interactive visualization for Internet security ieee visualization. pp. 505- 508 ,(2002) , 10.5555/602099.602181