University of Tasmania
Browse

File(s) under permanent embargo

NetflowVis: a temporal visualization system for netflow logs analysis

conference contribution
posted on 2023-05-23, 11:36 authored by He, L, Tang, B, Zhu, M, Lu, B, Huang, W
Netflow logs record the interactions between host pairs on both sides of the monitored border, and have got more attention from researchers for security concerns. Such data allows analysts to find interesting patterns and security anomalies. Visual analytics provides interaction and visualization techniques that can support these tasks. In this paper, we present a system called NetflowVis to analyze communication patterns and network abnormalities from netflow logs. This system consists of four views, including the communication trajectories view, the traffic line view, the snapshot view and the protocol view. The communication trajectories view is a composite view that dynamically describes the communication trajectories. This view combines a link-node tree and an improved ThemeRiver. The protocol view is designed to display statistical data of the upstream and downstream traffic on different protocols, which is an improved radial view based on an area filling strategy. The system provides a multilevel analysis architecture for netflow cognition. In this paper, we also present a case study to demonstrate the effectiveness and usefulness of our system.

History

Publication title

Lecture Notes in Computer Science 9929: Proceedings of the 13th International Conference on Cooperative Design, Visualization, and Engineering (CDVE 2016)

Editors

Y Luo

Pagination

202-209

ISBN

978-3-319-46770-2

Department/School

School of Information and Communication Technology

Publisher

Springer

Place of publication

New York, USA

Event title

13th International Conference on Cooperative Design, Visualization, and Engineering (CDVE 2016)

Event Venue

Sydney, Australia

Date of Event (Start Date)

2016-10-24

Date of Event (End Date)

2016-10-27

Rights statement

Copyright 2016 Springer International Publishing

Repository Status

  • Restricted

Socio-economic Objectives

Expanding knowledge in the information and computing sciences

Usage metrics

    University Of Tasmania

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC