A Novel Visualization Method for Detecting DDoS Network Attacks
|
|
|
- Sherilyn Morris
- 9 years ago
- Views:
Transcription
1 A Novel Visualization Method for Detecting DDoS Network Attacks Jiawan Zhang 1, Guoqiang Yang 1, Liangfu Lu 2,*, Mao Lin Huang 3, 1. School of Computer Science and Technology, Tianjin University, Tianjin,P.R.China; 2. Mathematics Department, Tianjin University, Tianjin, P.R.China, ; 3. Faculty of information Technology, University of Technology, Sydney, Australia *Corresponding Author Abstract. With the rapid growth of networks in size and complexity, netwok administrators today are facing more and more challenges for protecting their networked computers and other devices from all kinds of attacks. Unlike the traditional methods of analyzing textual log data, a visual interactive system called DDoSViewer is proposed in this paper for detecting DDoS kind of network attacks. DDoSViewer is specifically designed for detecting DDoS attacks through the analysis of visual patterns. We will discuss the data sources, visual structures and interactive functions that are used in the proposed visualization system. We will also discuss the advantages and disadvantages of the existing visual solutions for DDoS detection. The extraction and analysis of network data, the calculation and display of graphic elements attributes and the pre-characteristics of DDoS attacks are all included in the new visualization technique. The experiments showed that the new system can detect DDoS attacks effectively. Keywords: network security; DDoS attacks; information visualization; port scan 1 Introduction Networks and data communication systems are becoming more and more complex [1]. However, there is no absolute solution to secure a networked system perfectly. Most existing network security techniques and tools still rely heavily on human detection of intrusions. These techniques require users to analyze and detect the anomalies and intrusions manually. To enhance the human perception and understanding of all kinds of network intrusion and attacks, network visualization has become a hot research field in recent years that attempts to speed up the intrusion detection process through the visual analytics. Unlike the traditional methods of analyzing textual log data, visualization can increase the efficiency and effectiveness of network intrusion detection significantly. It can not only help analysts to deal with the large-volume of analytical network data effectively, but also help network administrators to detect anomalies through the pattern recognition in visual graphs. It can even be used for discovering new types of attacks and forecasting the trend of unexpected events.
2 Some visualization techniques and tools have been proposed recently for detecting hostile attacks [2,3,4]. However, these techniques are more focusing on how to produce novel visual structures for general real-time monitoring of large volume of network traffic data, and they are not specifically designed for detecting DDoS (Distributed Denial of Service) attacks. Up to now there are no specific tools available for DDoS attack detection. This paper proposes a novel visualization system called DDoSViewer that uses a new visual representation to display the main features and characteristics of DDoS attack. The proposed technique utilizes a variety of visual elements to map a collection of datagram to the graph for emphasizing DDoS patterns. The focus+context viewing and interaction techniques used in our system will also be discussed. The experiments have shown that the new system is able to detect port scans and many other kinds of DDoS attacks quickly and effectively. The rest of the paper is organized as follows. Section 2 presents some of the related work. We describe our approach in section 3, including the details of data collection and processing, nodes coordinates calculation and their visualization. Case studies are shown in section 4. Finally, we give the conclusions and future work in section 5. 2 Related work The study of DDoS attack detection has been popular for the last decade. Some works have been done in finding ways to detect DDoS attacks in large-volume alerts produced detection tools which employed visualization methods. Pearlman [5] proposed a new visualization in 2007 for network security by approaching the problem from a service-oriented perspective. This research provides a real time system for network administrators to monitor service activities, enabling for the early stage detection of attacks, including Denial of Service (DoS) attacks. Chris Lee etc [6] proposed a VisualFirewall in 2005 that seeks to aid in the configuration of firewalls and monitoring of networks by providing four simultaneous views that display varying levels of detail and time-scales as well as correctly visualizing firewall reactions to individual packets. Christos etc [7] introduced 3D interactive autostereoscopic (AS) displays for visual representations of attacks. Although the above visualization techniques can assist network analysts in analyzing abnormal (or unusual) patterns of network data in the early stage of network intrusion detection, they can only produce alarms and in most cases the accuracy rate of alarming for real attacks is very low. Therefore, the actual identifications and classifications of a variety of attacks are still relied on human brain. Furthermore, so far there is no specific tools developed for detecting DDoS attacks, and the above approaches are only focusing on the visualization of suspicious network activities and they do not help in the analysis of network event characteristics. In this work, we focused on both the analysis of DDoS features and the investigation of novel visual representations. This enables the new system work effectively in some complex situations for DDoS attack detections, such as Smurf attacks detection, port scans detection etc.
3 3 Our new approach: DDoSViewer Network Visualization (NV) is a part of the information visualization. The main steps involved in NV are 1) data collection and pre-process, 2) visual mapping, and 3) graphics generation. we will discuss these three steps with the details in the design stage. 3.1 Data collection and pre-process The current network security requires information visualization to be able to display sufficient network information with a meaningful visual format, and efficiency in visual processing. The multiple-dimensional visualization of raw network data is one of such meaningful visual format that attracted many researches working on it for several years. In multi-dimensional visualization, the dimension reduction technique is essential to be considered first, and then the format of the data including source IP, destination IP, destination port, packet size and time-stamp can be obtained accordingly. To analyze the raw data, a hash-table is used for data storage, and the keywords are expressed by the strings, which includes three parts: source IP, port numbers and time-stamps which are chosen by user to set the time interval K. Any difference of the three parts in the new element will be inserted into the hash-table, and will be rendered as a new node, which expresses the relationship between the two hosts. The value of K denotes the total amount of data transmitted between two linked nodes. After having selected a time interval K in the interface (default value as the beginning of the programming), K will be introduced into the statistical module. Statistical module uses the window that built by the scale of K processing the data from the beginning of the raw data to the end. The data which included in the scale of K will be processed and the others will not. 3.2 Drawing of Nodes The key to the visualization is drawing of the nodes for showing the present network status. Thus, the calculation of the geometrical positioning of nodes is essential. In our work the principle of the nodes positioning is based on the geometrical distance and the communication frequency between the new node and the center node which have the same trend. That is, if a console node communicates with the central console node more frequently, it will be moved away from the central one more further. There are two core issues for better visualization: 1). Positioning a new node: Based on the communicated frequency, the liner distance between a Console Node n c and the Central Console Node n cc is calculated by the following model. First, we define some constants and valuables: Fmax is the maximum communicated frequency, F min is the minimum communicated frequency, and max is the maximum radius of the available R
4 screen space. Runit is a unit radius that is defined in formula (2), where d represents the greatest difference of the frequency defined in formula (1). Suppose that F n is the frequency value of a new console node n c calculated from statisticas. R n is the radius of n c, defined by formula (3). After we get the radius, we can calculate the geometrical position of n c, D(n c )=(x, y) using formula (4). In Fig. 1, the point O is the Center Console Node n cc, and n c is a new console node. The absolute value of the abscissa of the point X is in the range of [- R, x R ]. x Using the formula (4) we can obtain the values, and then we can calculate y using (5). d F max F min =. (1) R max R unit =. d (2) Rx = Fx Runit. (3) x = Random( ) Rx. (4) R x x y y y R x x y x = ( 0) + ( 0) = ± x ( 0) + 0. (5) Fig: 1. Node positioning 2) Node overlapping problem: If some nodes are overlapped in the visualization, then the main graphic attributes of nodes may not be completely displayed. For example, the attributes of the line between console nodes and the colors of the console nodes may be hidden when node overlap occurs. In our visualization, we addressed
5 this problem with an effective and simple method. When a new node is to be generated, the visualization will search all the existing positions of displayed nodes. If there is a node overlap found, the system will then re-generate a new X coordinate, and a new Y coordinate for the new node. However, this problem cannot be completely solved. Although the scope of the X, Y coordinates is sequential and unlimited, we still can not obtain a clear view with no node overlaps if the number of nodes to be displayed in the same radius becomes large. Considering the arc length with the same radius is always limited, and the size of the node can t be modified. The technique of magnifier can be used to solve this problem by adjusting Runit defined in the formula (2) manually. It can be enlarged in the local view through adjusting the parameters to achieve amplification. This will be discussed in the next section. 3.3 Graphic Design of Nodes After the positioning of nodes,, the information of the geometrical location of nodes (date items) will be stored in the program, and then the nodes will be drawn graphically through the graphic design module, which is depends on the domain characteristics of nodes. The graphic design model can be described below: The networking connection between a node n c and n cc can be described by several domain specific attributes and the value of these attributes can be measured in a certain time interval K. In our graphic design, we attempted to map the domain specific attribute (the networking attributes) into the graphical attributes (the coloring scheme). For example, we may use the red color to represent the high value of a certain networking attribute. In our graphic model, a console node n c is consisting of a range of concentric circles, and the number of ports involved in the networking connection is represented by the color contrast grade. Each node is displayed as a range of concentric circles (see Fig 2) which have equal width between each pair of circles, C i and C i+1. Each circle displays one color in a N-level color scheme (see Fig 2). The color of the consecutive circle is mapped the consecutive color ribbon. At the same time the width P express the distance between the consecutive colors. The width P is determined by the number of the ports connected between nodes n c and n cc. If the connection is based on many ports, the span between colors would be very larger and the nodes color contrast grade would be stronger. Oppositely, the span could be smaller and its color trends to be a single color. All of these are shown in Fig. 2[13]
6 Fig. 2: The color scheme in node design For detecting different abnormities and identifying different types of attacks, we need to utilize different value of the parameters. Therefore the adjustment of the parameter is critical to the system. The characteristics of DDoS attack are best to be presented by multidimensional and large scale visualizations. However the limit of the display space is a problem. Therefore, the interactive zooming technique is crucial for users to have both the global view of the nodes interaction and the detail view of a node that can help in identifying the type of attacks. In this model, the user can adjust the value of parameters in the system to catch the optimized view for detecting abnormal actions. For example, the user can manually adjust the length of radius and the time intervals K in the real-time raw data to catch the most distinctive features of DDoS attacks. 4 Case studies In this section we describe several examples of using DDoSViewer for visual analysis and detection of DDoS attacks. One remarkable characteristic of DDoS attacks can be described as that in a short time the attacked host receives a lot of date packets sending from a large number of strange IP addresses. For example, the characteristic of Smurf attack is that in a short time one host may communicate with large number of IP addresses simultaneously and most of the source IP addresses have never appeared in the current host before. The experimental data we used are caught from LNA in the Image and Graphics Institute, Tianjin University. By using DDoSViewer, DDoS attacks can be detected very easily. In Fig. 3, there are three isolated nodes around the center host. The interactive technique allows the exploration of detailed attributes of nodes easily. By having a close look of detailed data shown in Fig 3, we can easily find that these network connections are mainly related to port 23 and 80. Thus, the analysts may assume that these nodes may perform data transmission services, such as ftp transmissions (in port 23) or web transmissions (in port 80), and there is nothing abnormal. In comparison with other nodes, the line color between the third node and the center host is deeper (the red
7 color), and from Fig. 3, we can see that there are more data communications with port of one host. If we want to have a close look of this host, we can get its IP address So it can be assumed that the user is using a file transfer service. We can also see that there are many nodes surrounding the center node in Fig. 3. After interactively exploring the detail of nodes, we discovered that all of the surrounding nodes have different IP addresses. All log data items are collected in the same time interval: K=2. By looking over detailed information of these surrounding nodes, we also found that all the nodes are connecting with the port 7 of the center host at the same time: :05:02. The sizes of the transmitted data between the surrounding nodes and the center host are very small. It could be just an Echo message, such as a returned message after the host receives a PING packet. Therefore, we can then identify this visual pattern shown in Fig 3 as a typical Smurf attack, which is quiet different from the other patterns we generated through DDoSViewer. In fact, our system can detect Smurf attacks that are not restricted to the Echo package. Rather the system could extend its pattern recognition capacity to identify other abnormalities (or attacks) based on the distinctive features of the visualization generated by DDoSViewer. Fig. 3: A distinctive pattern of Smurf attack: many nodes surrounding the host node with small data packages and stranger IP addresses. Port-Scan is another preliminary type of DDoS attacks and we can also extract its main domain specific features and generate distinctive visual patterns for analysts to quickly detect it. In Fig. 4, we can see that there are two obvious abnormal nodes, the first node and the second node. In comparison with other nodes in visualization (for example nodes in group A), these nodes are far away from the center node. The main features of abnormal nodes are that they have more color levels than others and they also have a larger amount of networking traffic (data transmissions) with the center node. In Fig. 5, we can easily find that in each port of the abnormal nodes only transfer a very small data package, but the scanned ports received a large-volume of data, and the colors of the abnormal nodes are very complicated. We believe that the distinctive visual pattern generated as shown in Fig 4 is clear enough for network analysts to easily and quickly identifying the port-scan attackers.
8 Fig. 4: A distinctive pattern of port-scan attack. Fig. 5: the detail information of nodes displayed in Fig 4. 5 Conclusion and future work This paper proposed a new visualization method called DDoSViewer that focuses on creating of distinctive visual patterns for analysts to effectively and efficiently detect DDoS attacks, such as the Smurf attacks and port-scan attacks. The new system is working mainly based on the statistics model of the time-stamp, rather than the
9 traditional packets analysis model. Interaction techniques with multiple-views are used to display both the overall view of the linkage attributes and the detailed view of node attributes, which are represented by geometrical attributes and rich graphic properties, such as colors and the locality of nodes.. The experiments have shown that the pattern of the attacks can be distinctively generated in DDoSViewer and these distinctive patterns could significantly assist the analysts in detecting DDoS attacks. In the future, we plan to draw the graphics in 3D visual spaces, and set up more visualization functions to improve the representations of nodes that could increase the accuracy of network attack detections. Acknowledgments: This work has been supported by National Natural Science Foundation of China under Grant No ;the Natural Science Foundation of Tianjin, P.R. of China, under Grant No. 07F2030. References 1. X. Yin, W. Yurcik,: et al. VisFlowConnect: NetFlow Visualizations of Link Relationships for Security Situational Awareness., Proceedings of the 2004 ACM Workshop on Visualization and Data Mining for Computer Security, Washington, DC, USA, ACM Press. 2. Robert F. Erbacher.: Visual traffic monitoring and evaluation, In Proceedings of the Conference on Internet Performance and Control of Network Systems II, 2001, pp L. Girardin and D. Brodbeck.: A visual approach for monitoring logs, In Proceedings of the 12th Usenix System Administration conference, 1998, pp Chris Muelder, Kwan-Liu Ma and Tony Bartoletti,: A Visualization Methodology for Characterization of Network Scans, Visualization for Computer Security, 2005, pp J. Pearlman, P.R.: Visualizing Network Security Events Using Compound Glyphs from a Service-Oriented Perspective, In Visualization for Computer Security. VizSEC 2007: Proceedings of the Workshop on Visualization for Computer Security, 2007, pp. 131~ Chris P. Lee, J.T., Nicholas Gibbs,Raheem Beyah,John A. Copeland.: Visual Firewall: Realtime Network Security Monitor. in IEEE Workshop on Visualization for Computer Security 2005 (VizSEC 05), 2005:129~ Christos Papadopoulos, C.K., Alexander Sawchuk, Xinming He, CyberSeer: 3D Audio- Visual Immersion for Network Security and Management., Proceedings 2004 ACM Workshop on Visualization and Data Mining for Computer Security Washington, DC, USA: ACM Press,pp: 90~ A. Hussain, J.H.a.C.P.: A Framework for Classifying Denial of Service Attacks. in Sigcomm Karlsruhe, Germany. 2003: 99~ Muelder, C., Ma, K.L., Bartoletti, T.: A visualization methodology for characterization of network scans. Visualization for Computer Security, IEEE Workshops, 2005, pp Conti, G., Abdullah, K.: Passive visual fingerprinting of network attack tools. VizSEC/DMSEC 04: Proceedings of the 2004 ACM Workshop on Visualization and Data Mining for Computer Security, 2004,pp Jonathan McPherson, Kwan-Liu Ma, Paul Krystosk, Tony Bartoletti, Marvin Christensen.: Portvis: A tool for port-based detection of security events. In: ACM VizSEC 2004 Workshop, 2004, pp Pin Ren, Yan Gao and Zhichun Li,: IDGraphs: Intrusion Detection and Analysis Using Histographs, Visualization for Computer Security, 2005, pp.39-46
10 13. Stuart K. Card, Jock D. Mackinlay and Ben Shneiderman,: Readings in information visualization: using vision to think, Morgan Kaufmann Publishers, Rawiroj Robert Kasemsri,: A Survey, Taxonomy, and Analysis of Network Security Visualization Techniques :[Master Paper], USA, Georgia State University, Richard A. Becker, Stephen G. Eick, and Allan R.Wilks, Visualizing network data. IEEE Transactions on Visualization and ComputerGraphics,1995 1(1):pp Prefuse, Mukosaka, S.;,Koike, H.: Integrated visualization system for monitoring security in largescale local area network Visualization,APVIS ' th International Asia-Pacific Symposium, 2007,pp Musa, Shahrulniza, Parish,etc.: Visualizing Communication Network Security Attacks, Information Visualization,IV '07. 11th Internati onal Conference, 2007, pp Pavel Minarik1, Tomas Dymacek.: NetFlow Data Visualization Based on Graphs, In Visualization for Computer Security,VizSEC 2008: Proceedings of the Workshop on Visualization for Computer Security, 2008, pp
A Visualization Technique for Monitoring of Network Flow Data
A Visualization Technique for Monitoring of Network Flow Data Manami KIKUCHI Ochanomizu University Graduate School of Humanitics and Sciences Otsuka 2-1-1, Bunkyo-ku, Tokyo, JAPAPN [email protected]
Visualization for Network Traffic Monitoring & Security
Visualization for Network Traffic Monitoring & Security Erwan ISIT/KYUSHU, Supélec 2006 Plan Visualization Visualization Host based Network based Between networks Other prototypes Pre-processing PGVis
Simplified Network Traffic Visualization for Real-Time Security Analysis
Simplified Network Traffic Visualization for Real-Time Security Analysis Matthew Dean and Lucas Vespa Department of Computer Science University of Illinois Springfield Springfield, IL 62703 Abstract Although
An Adaptable Innovative Visualization For Multiple Levels of Users
World Applied Sciences Journal 15 (5): 722-727, 2011 ISSN 1818-4952 IDOSI Publications, 2011 An Adaptable Innovative Visualization For Multiple Levels of Users Doris Hooi-Ten Wong and Sureswaran Ramadass
Application of Data Mining Techniques in Intrusion Detection
Application of Data Mining Techniques in Intrusion Detection LI Min An Yang Institute of Technology [email protected] Abstract: The article introduced the importance of intrusion detection, as well as
Visual Firewall: Real-time Network Security Monitor
Visual Firewall: Real-time Network Security Monitor Chris P. Lee Georgia Tech CSC Jason Trost Georgia Tech CS Dept Nicholas Gibbs Georgia Tech CS Dept Raheem Beyah Georgia Tech CSC John A. Copeland Georgia
A Review of Anomaly Detection Techniques in Network Intrusion Detection System
A Review of Anomaly Detection Techniques in Network Intrusion Detection System Dr.D.V.S.S.Subrahmanyam Professor, Dept. of CSE, Sreyas Institute of Engineering & Technology, Hyderabad, India ABSTRACT:In
Flamingo: Visualizing Internet Traffic
Flamingo: Visualizing Internet Traffic Jon Oberheide, Michael Goff, Manish Karir Networking Research and Development Merit Network Inc. Ann Arbor, MI 48104 USA {jonojono,goffm,mkarir}@merit.edu Abstract
Load Distribution in Large Scale Network Monitoring Infrastructures
Load Distribution in Large Scale Network Monitoring Infrastructures Josep Sanjuàs-Cuxart, Pere Barlet-Ros, Gianluca Iannaccone, and Josep Solé-Pareta Universitat Politècnica de Catalunya (UPC) {jsanjuas,pbarlet,pareta}@ac.upc.edu
TEXT-FILLED STACKED AREA GRAPHS Martin Kraus
Martin Kraus Text can add a significant amount of detail and value to an information visualization. In particular, it can integrate more of the data that a visualization is based on, and it can also integrate
Information Visualization of Attributed Relational Data
Information Visualization of Attributed Relational Data Mao Lin Huang Department of Computer Systems Faculty of Information Technology University of Technology, Sydney PO Box 123 Broadway, NSW 2007 Australia
Keywords Attack model, DDoS, Host Scan, Port Scan
Volume 4, Issue 6, June 2014 ISSN: 2277 128X International Journal of Advanced Research in Computer Science and Software Engineering Research Paper Available online at: www.ijarcsse.com DDOS Detection
Botnet Detection by Abnormal IRC Traffic Analysis
Botnet Detection by Abnormal IRC Traffic Analysis Gu-Hsin Lai 1, Chia-Mei Chen 1, and Ray-Yu Tzeng 2, Chi-Sung Laih 2, Christos Faloutsos 3 1 National Sun Yat-Sen University Kaohsiung 804, Taiwan 2 National
NetBytes Viewer: An Entity-based NetFlow Visualization Utility for Identifying Intrusive Behavior
NetBytes Viewer: An Entity-based NetFlow Visualization Utility for Identifying Intrusive Behavior Teryl Taylor, Stephen Brooks and John McHugh Abstract NetBytes Host Viewer is an interactive visualization
NVisionIP: An Interactive Network Flow Visualization Tool for Security
NVisionIP: An Interactive Network Flow Visualization Tool for Security Kiran Lakkaraju William Yurcik Ratna Bearavolu Adam J. Lee National Center for Supercomputing Applications (NCSA) University of Illinois,
VisFlowConnect-IP: A Link-Based Visualization of NetFlows for Security Monitoring
VisFlowConnect-IP: A Link-Based Visualization of NetFlows for Security Monitoring William Yurcik National Center for Supercomputing Applications (NCSA) University of Illinois at Urbana-Champaign [email protected]
Preserving the Big Picture: Visual Network Traffic Analysis with TNV
Preserving the Big Picture: Visual Network Traffic Analysis with TNV John R. Goodall Wayne G. Lutters Penny Rheingans Anita Komlodi University of Maryland, Baltimore County ABSTRACT When performing packet-level
Preserving the Big Picture: Visual Network Traffic Analysis with TNV
Preserving the Big Picture: Visual Network Traffic Analysis with TNV John R. Goodall Wayne G. Lutters Penny Rheingans Anita Komlodi University of Maryland, Baltimore County ABSTRACT When performing packet-level
A Measurement of NAT & Firewall Characteristics in Peer to Peer Systems
A Measurement of NAT & Firewall Characteristics in Peer to Peer Systems L. D Acunto, J.A. Pouwelse, and H.J. Sips Department of Computer Science Delft University of Technology, The Netherlands [email protected]
Botnet Detection Based on Degree Distributions of Node Using Data Mining Scheme
Botnet Detection Based on Degree Distributions of Node Using Data Mining Scheme Chunyong Yin 1,2, Yang Lei 1, Jin Wang 1 1 School of Computer & Software, Nanjing University of Information Science &Technology,
NVisionIP and VisFlowConnect-IP: Two Tools for Visualizing NetFlows for Security
NVisionIP and VisFlowConnect-IP: Two Tools for Visualizing NetFlows for Security William Yurcik National Center for Supercomputing Applications (NCSA) University of Illinois at
Hillstone T-Series Intelligent Next-Generation Firewall Whitepaper: Abnormal Behavior Analysis
Hillstone T-Series Intelligent Next-Generation Firewall Whitepaper: Abnormal Behavior Analysis Keywords: Intelligent Next-Generation Firewall (ingfw), Unknown Threat, Abnormal Parameter, Abnormal Behavior,
NSC 93-2213-E-110-045
NSC93-2213-E-110-045 2004 8 1 2005 731 94 830 Introduction 1 Nowadays the Internet has become an important part of people s daily life. People receive emails, surf the web sites, and chat with friends
Flexible Web Visualization for Alert-Based Network Security Analytics
Flexible Web Visualization for Alert-Based Network Security Analytics Lihua Hao 1, Christopher G. Healey 1, Steve E. Hutchinson 2 1 North Carolina State University, 2 U.S. Army Research Laboratory [email protected]
Network Intrusion Simulation Using OPNET
Network Intrusion Simulation Using OPNET Shabana Razak, Mian Zhou, Sheau-Dong Lang* School of Electrical Engineering & Computer Science and National Center for Forensic Science* University of Central Florida,
HIDS and NIDS Hybrid Intrusion Detection System Model Design Zhenqi Wang 1, a, Dankai Zhang 1,b
Advanced Engineering Forum Online: 2012-09-26 ISSN: 2234-991X, Vols. 6-7, pp 991-994 doi:10.4028/www.scientific.net/aef.6-7.991 2012 Trans Tech Publications, Switzerland HIDS and NIDS Hybrid Intrusion
An Efficient Way of Denial of Service Attack Detection Based on Triangle Map Generation
An Efficient Way of Denial of Service Attack Detection Based on Triangle Map Generation Shanofer. S Master of Engineering, Department of Computer Science and Engineering, Veerammal Engineering College,
Visual Analysis of Complex Firewall Configurations
Visual Analysis of Complex Firewall Configurations Florian Mansmann University of Konstanz [email protected] Timo Göbel University of Konstanz [email protected] William Cheswick [email protected]
Case Study: Instrumenting a Network for NetFlow Security Visualization Tools
Case Study: Instrumenting a Network for NetFlow Security Visualization Tools William Yurcik* Yifan Li SIFT Research Group National Center for Supercomputing Applications (NCSA) University of Illinois at
A Flow-based Method for Abnormal Network Traffic Detection
A Flow-based Method for Abnormal Network Traffic Detection Myung-Sup Kim, Hun-Jeong Kang, Seong-Cheol Hong, Seung-Hwa Chung, and James W. Hong Dept. of Computer Science and Engineering POSTECH {mount,
Network Instruments white paper
Network Instruments white paper USING A NETWORK ANALYZER AS A SECURITY TOOL Network Analyzers are designed to watch the network, identify issues and alert administrators of problem scenarios. These features
Safely Sharing Data Between CSIRTs: The SCRUB* Security Anonymization Tool Infrastructure
Safely Sharing Data Between CSIRTs: The SCRUB* Security Anonymization Tool Infrastructure William Yurcik* Clay Woolam, Greg Hellings, Latifur Khan, Bhavani Thuraisingham University
Security visualisation
Security visualisation This thesis provides a guideline of how to generate a visual representation of a given dataset and use visualisation in the evaluation of known security vulnerabilities by Marco
Real-Time Interactive Visual Port Monitoring and Analysis
Real-Time Interactive Visual Port Monitoring and Analysis Robert F. Erbacher 1 and Menashe Garber 2 1 Utah State University, Dept. of Computer Science, UMC 4205, Logan, UT 84322, Phone: 435-797-3291, Fax:
Cover. White Paper. (nchronos 4.1)
Cover White Paper (nchronos 4.1) Copyright Copyright 2013 Colasoft LLC. All rights reserved. Information in this document is subject to change without notice. No part of this document may be reproduced
How To Detect Denial Of Service Attack On A Network With A Network Traffic Characterization Scheme
Efficient Detection for DOS Attacks by Multivariate Correlation Analysis and Trace Back Method for Prevention Thivya. T 1, Karthika.M 2 Student, Department of computer science and engineering, Dhanalakshmi
Situational Awareness Through Network Visualization
CYBER SECURITY DIVISION 2014 R&D SHOWCASE AND TECHNICAL WORKSHOP Situational Awareness Through Network Visualization Pacific Northwest National Laboratory Daniel M. Best Bryan Olsen 11/25/2014 Introduction
Tudumi: Information Visualization System for Monitoring and Auditing Computer Logs
Tudumi: Information Visualization System for Monitoring and Auditing Computer Logs Tetsuji Takada Satellite Venture Business Lab. University of Electro-Communications [email protected] Hideki Koike Graduate
CHAPTER 1 INTRODUCTION
21 CHAPTER 1 INTRODUCTION 1.1 PREAMBLE Wireless ad-hoc network is an autonomous system of wireless nodes connected by wireless links. Wireless ad-hoc network provides a communication over the shared wireless
Name. Description. Rationale
Complliiance Componentt Description DEEFFI INITION Network-Based Intrusion Detection Systems (NIDS) Network-Based Intrusion Detection Systems (NIDS) detect attacks by capturing and analyzing network traffic.
Big Data Classification: Problems and Challenges in Network Intrusion Prediction with Machine Learning
Big Data Classification: Problems and Challenges in Network Intrusion Prediction with Machine Learning By: Shan Suthaharan Suthaharan, S. (2014). Big data classification: Problems and challenges in network
International Journal of Computer Science Trends and Technology (IJCST) Volume 3 Issue 3, May-June 2015
RESEARCH ARTICLE OPEN ACCESS Data Mining Technology for Efficient Network Security Management Ankit Naik [1], S.W. Ahmad [2] Student [1], Assistant Professor [2] Department of Computer Science and Engineering
A Survey, Taxonomy, and Analysis of Network Security Visualization Techniques
Georgia State University ScholarWorks @ Georgia State University Computer Science Theses Department of Computer Science 1-12-2006 A Survey, Taxonomy, and Analysis of Network Security Visualization Techniques
An apparatus for P2P classification in Netflow traces
An apparatus for P2P classification in Netflow traces Andrew M Gossett, Ioannis Papapanagiotou and Michael Devetsikiotis Electrical and Computer Engineering, North Carolina State University, Raleigh, USA
An Anomaly-Based Method for DDoS Attacks Detection using RBF Neural Networks
2011 International Conference on Network and Electronics Engineering IPCSIT vol.11 (2011) (2011) IACSIT Press, Singapore An Anomaly-Based Method for DDoS Attacks Detection using RBF Neural Networks Reyhaneh
Science Park Research Journal
2321-8045 Science Park Research Journal Original Article th INTRUSION DETECTION SYSTEM An Approach for Finding Attacks Ashutosh Kumar and Mayank Kumar Mittra ABSTRACT Traditionally firewalls are used to
Taxonomy of Intrusion Detection System
Taxonomy of Intrusion Detection System Monika Sharma, Sumit Sharma Abstract During the past years, security of computer networks has become main stream in most of everyone's lives. Nowadays as the use
Characterization and Analysis of NTP Amplification Based DDoS Attacks
Characterization and Analysis of NTP Amplification Based DDoS Attacks L. Rudman Department of Computer Science Rhodes University Grahamstown [email protected] B. Irwin Department of Computer Science
Application of Netflow logs in Analysis and Detection of DDoS Attacks
International Journal of Computer and Internet Security. ISSN 0974-2247 Volume 8, Number 1 (2016), pp. 1-8 International Research Publication House http://www.irphouse.com Application of Netflow logs in
Hadoop Technology for Flow Analysis of the Internet Traffic
Hadoop Technology for Flow Analysis of the Internet Traffic Rakshitha Kiran P PG Scholar, Dept. of C.S, Shree Devi Institute of Technology, Mangalore, Karnataka, India ABSTRACT: Flow analysis of the internet
Christopher W. Muelder
Christopher W. Muelder Contact Information Kemper Hall 2136 Voice: (530) 752-9143 University of California, Davis Fax: (530) 752-4767 1 Shields Ave. E-mail: [email protected] Davis, CA 95616 USA WWW:
On Entropy in Network Traffic Anomaly Detection
On Entropy in Network Traffic Anomaly Detection Jayro Santiago-Paz, Deni Torres-Roman. Cinvestav, Campus Guadalajara, Mexico November 2015 Jayro Santiago-Paz, Deni Torres-Roman. 1/19 On Entropy in Network
A Small-time Scale Netflow-based Anomaly Traffic Detecting Method Using MapReduce
, pp.231-242 http://dx.doi.org/10.14257/ijsia.2014.8.2.24 A Small-time Scale Netflow-based Anomaly Traffic Detecting Method Using MapReduce Wang Jin-Song, Zhang Long, Shi Kai and Zhang Hong-hao School
An Evaluation of Machine Learning Method for Intrusion Detection System Using LOF on Jubatus
An Evaluation of Machine Learning Method for Intrusion Detection System Using LOF on Jubatus Tadashi Ogino* Okinawa National College of Technology, Okinawa, Japan. * Corresponding author. Email: [email protected]
INCREASE NETWORK VISIBILITY AND REDUCE SECURITY THREATS WITH IMC FLOW ANALYSIS TOOLS
WHITE PAPER INCREASE NETWORK VISIBILITY AND REDUCE SECURITY THREATS WITH IMC FLOW ANALYSIS TOOLS Network administrators and security teams can gain valuable insight into network health in real-time by
Network- vs. Host-based Intrusion Detection
Network- vs. Host-based Intrusion Detection A Guide to Intrusion Detection Technology 6600 Peachtree-Dunwoody Road 300 Embassy Row Atlanta, GA 30348 Tel: 678.443.6000 Toll-free: 800.776.2362 Fax: 678.443.6477
System for Denial-of-Service Attack Detection Based On Triangle Area Generation
System for Denial-of-Service Attack Detection Based On Triangle Area Generation 1, Heena Salim Shaikh, 2 N Pratik Pramod Shinde, 3 Prathamesh Ravindra Patil, 4 Parag Ramesh Kadam 1, 2, 3, 4 Student 1,
NETWORK-BASED INTRUSION DETECTION USING NEURAL NETWORKS
1 NETWORK-BASED INTRUSION DETECTION USING NEURAL NETWORKS ALAN BIVENS [email protected] RASHEDA SMITH [email protected] CHANDRIKA PALAGIRI [email protected] BOLESLAW SZYMANSKI [email protected] MARK
CTS2134 Introduction to Networking. Module 8.4 8.7 Network Security
CTS2134 Introduction to Networking Module 8.4 8.7 Network Security Switch Security: VLANs A virtual LAN (VLAN) is a logical grouping of computers based on a switch port. VLAN membership is configured by
Detection of Distributed Denial of Service Attack with Hadoop on Live Network
Detection of Distributed Denial of Service Attack with Hadoop on Live Network Suchita Korad 1, Shubhada Kadam 2, Prajakta Deore 3, Madhuri Jadhav 4, Prof.Rahul Patil 5 Students, Dept. of Computer, PCCOE,
Mining and Detecting Connection-Chains in Network Traffic
Mining and Detecting Connection-Chains in Network Traffic Ahmad Almulhem and Issa Traore ISOT Research Lab, ECE Department, University of Victoria, Victoria, CANADA Summary. A connection-chain refers to
Flow-based Worm Detection using Correlated Honeypot Logs
Flow-based Worm Detection using Correlated Honeypot Logs Falko Dressler, Wolfgang Jaegers, and Reinhard German Computer Networks and Communication Systems, University of Erlangen, Martensstr. 3, 91058
The Truth about False Positives
An ISS Technical White Paper The Truth about False Positives 6303 Barfield Road Atlanta, GA 30328 Tel: 404.236.2600 Fax: 404.236.2626 Overview In the security industry, many security analysts remark that
A TWO LEVEL ARCHITECTURE USING CONSENSUS METHOD FOR GLOBAL DECISION MAKING AGAINST DDoS ATTACKS
ICTACT JOURNAL ON COMMUNICATION TECHNOLOGY, JUNE 2010, ISSUE: 02 A TWO LEVEL ARCHITECTURE USING CONSENSUS METHOD FOR GLOBAL DECISION MAKING AGAINST DDoS ATTACKS S.Seetha 1 and P.Raviraj 2 Department of
Exploration on Security System Structure of Smart Campus Based on Cloud Computing. Wei Zhou
3rd International Conference on Science and Social Research (ICSSR 2014) Exploration on Security System Structure of Smart Campus Based on Cloud Computing Wei Zhou Information Center, Shanghai University
Intrusion Log Sharing University of Wisconsin-Madison
Intrusion Log Sharing University of Wisconsin-Madison John Bethencourt ([email protected]) Jason Franklin ([email protected]) Mary Vernon ([email protected]) 1 Talk Outline Background: Blacklists,
Research on Errors of Utilized Bandwidth Measured by NetFlow
Research on s of Utilized Bandwidth Measured by NetFlow Haiting Zhu 1, Xiaoguo Zhang 1,2, Wei Ding 1 1 School of Computer Science and Engineering, Southeast University, Nanjing 211189, China 2 Electronic
Layered Approach of Intrusion Detection System with Efficient Alert Aggregation for Heterogeneous Networks
Layered Approach of Intrusion Detection System with Efficient Alert Aggregation for Heterogeneous Networks Lohith Raj S N, Shanthi M B, Jitendranath Mungara Abstract Protecting data from the intruders
A Review on Network Intrusion Detection System Using Open Source Snort
, pp.61-70 http://dx.doi.org/10.14257/ijdta.2016.9.4.05 A Review on Network Intrusion Detection System Using Open Source Snort Sakshi Sharma and Manish Dixit Department of CSE& IT MITS Gwalior, India [email protected],
Take the Red Pill: Becoming One with Your Computing Environment using Security Intelligence
Take the Red Pill: Becoming One with Your Computing Environment using Security Intelligence Chris Poulin Security Strategist, IBM Reboot Privacy & Security Conference 2013 1 2012 IBM Corporation Securing
packet retransmitting based on dynamic route table technology, as shown in fig. 2 and 3.
Implementation of an Emulation Environment for Large Scale Network Security Experiments Cui Yimin, Liu Li, Jin Qi, Kuang Xiaohui National Key Laboratory of Science and Technology on Information System
A Visualization Paradigm for Network Intrusion Detection
Proceedings of the 2005 IEEE Workshop on Information Assurance and Security United States Military Academy, West Point, NY, 17 19 June 2005 A Visualization Paradigm for Network Intrusion Detection Yarden
How To Classify A Dnet Attack
Analysis of Computer Network Attacks Nenad Stojanovski 1, Marjan Gusev 2 1 Bul. AVNOJ 88-1/6, 1000 Skopje, Macedonia [email protected] 2 Faculty of Natural Sciences and Mathematics, Ss. Cyril
Guide to DDoS Attacks December 2014 Authored by: Lee Myers, SOC Analyst
INTEGRATED INTELLIGENCE CENTER Technical White Paper William F. Pelgrin, CIS President and CEO Guide to DDoS Attacks December 2014 Authored by: Lee Myers, SOC Analyst This Center for Internet Security
FIREWALLS. Firewall: isolates organization s internal net from larger Internet, allowing some packets to pass, blocking others
FIREWALLS FIREWALLS Firewall: isolates organization s internal net from larger Internet, allowing some packets to pass, blocking others FIREWALLS: WHY Prevent denial of service attacks: SYN flooding: attacker
A Frequency-Based Approach to Intrusion Detection
A Frequency-Based Approach to Intrusion Detection Mian Zhou and Sheau-Dong Lang School of Electrical Engineering & Computer Science and National Center for Forensic Science, University of Central Florida,
Prediction of DDoS Attack Scheme
Chapter 5 Prediction of DDoS Attack Scheme Distributed denial of service attack can be launched by malicious nodes participating in the attack, exploit the lack of entry point in a wireless network, and
Bandwidth based Distributed Denial of Service Attack Detection using Artificial Immune System
Bandwidth based Distributed Denial of Service Attack Detection using Artificial Immune System 1 M.Yasodha, 2 S. Umarani 1 PG Scholar, Department of Information Technology, Maharaja Engineering College,
A Novel Distributed Denial of Service (DDoS) Attacks Discriminating Detection in Flash Crowds
International Journal of Research Studies in Science, Engineering and Technology Volume 1, Issue 9, December 2014, PP 139-143 ISSN 2349-4751 (Print) & ISSN 2349-476X (Online) A Novel Distributed Denial
Nemea: Searching for Botnet Footprints
Nemea: Searching for Botnet Footprints Tomas Cejka 1, Radoslav Bodó 1, Hana Kubatova 2 1 CESNET, a.l.e. 2 FIT, CTU in Prague Zikova 4, 160 00 Prague 6 Thakurova 9, 160 00 Prague 6 Czech Republic Czech
Firewalls Netasq. Security Management by NETASQ
Firewalls Netasq Security Management by NETASQ 1. 0 M a n a g e m e n t o f t h e s e c u r i t y b y N E T A S Q 1 pyright NETASQ 2002 Security Management is handled by the ASQ, a Technology developed
Visualization of Host Behavior for Network Security
Visualization of Host Behavior for Network Security Florian Mansmann, Lorenz Meier, and Daniel A. Keim Abstract Monitoring host behavior in a network is one of the most essential tasks in the fields of
Efficiently Managing Firewall Conflicting Policies
Efficiently Managing Firewall Conflicting Policies 1 K.Raghavendra swamy, 2 B.Prashant 1 Final M Tech Student, 2 Associate professor, Dept of Computer Science and Engineering 12, Eluru College of Engineeering
Bridging the gap between COTS tool alerting and raw data analysis
Article Bridging the gap between COTS tool alerting and raw data analysis An article on how the use of metadata in cybersecurity solutions raises the situational awareness of network activity, leading
