NetflowVis: A temporal visualization system for netflow logs analysis

7Citations
Citations of this article
4Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Netflow logs record the interactions between host pairs on both sides of the monitored border, and have got more attention from researchers for security concerns. Such data allows analysts to find interesting patterns and security anomalies. Visual analytics provides interaction and visualization techniques that can support these tasks. In this paper, we present a system called NetflowVis to analyze communication patterns and network abnormalities from netflow logs. This system consists of four views, including the communication trajectories view, the traffic line view, the snapshot view and the protocol view. The communication trajectories view is a composite view that dynamically describes the communication trajectories. This view combines a link-node tree and an improved ThemeRiver. The protocol view is designed to display statistical data of the upstream and downstream traffic on different protocols, which is an improved radial view based on an area filling strategy. The system provides a multilevel analysis architecture for netflow cognition. In this paper, we also present a case study to demonstrate the effectiveness and usefulness of our system.

Cite

CITATION STYLE

APA

He, L., Tang, B., Zhu, M., Lu, B., & Huang, W. (2016). NetflowVis: A temporal visualization system for netflow logs analysis. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 9929 LNCS, pp. 202–209). Springer Verlag. https://doi.org/10.1007/978-3-319-46771-9_27

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free