z-logo
open-access-imgOpen Access
On Multilateral Security Monitoring and Analysis With an Abstract Tomogram of Network Flows
Author(s) -
Young Yoon,
Yongjun Choi
Publication year - 2018
Publication title -
ieee access
Language(s) - English
Resource type - Journals
SCImago Journal Rank - 0.587
H-Index - 127
ISSN - 2169-3536
DOI - 10.1109/access.2018.2829910
Subject(s) - aerospace , bioengineering , communication, networking and broadcast technologies , components, circuits, devices and systems , computing and processing , engineered materials, dielectrics and plasmas , engineering profession , fields, waves and electromagnetics , general topics for engineers , geoscience , nuclear engineering , photonics and electrooptics , power, energy and industry applications , robotics and control systems , signal processing and analysis , transportation
In this paper, we present a novel method for visualizing an abstract tomogram of network flows. Through a tomogram, we offer visual cues for quickly sensing aggregate and temporal networking behaviors of the monitored systems. In an integrated view of a tomogram, users can cut across a specific dimension to reason about interesting networking activities without losing the overall picture of the networked system. We extend this tomogram with user interfaces for finding correlation between network flows and their attributes using a co-occurrence analysis algorithm. This paper also presents an interface for conducting sequence mining for interested flows in order to infer causal relationships. Security engineers need to prioritize the aforementioned situation analysis tasks by focusing on endpoints with relatively higher security risks. To help security engineers with this task, we devise a way to assess and visualize the security risks according to a new centrality measure that is computed based on various networking information from a set of network flows. Our paper shows that the novel visualization method and analytics interfaces offer more intuitive means to track down complicated symptoms of advanced and covert security threats.

The content you want is available to Zendy users.

Already have an account? Click here to sign in.
Having issues? You can contact us here
Accelerating Research

Address

John Eccles House
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom