Abstract
Intrusion detection and prevention systems (IDPSs) are at the core of protecting an enterprise's network. In general, IDPSs use pre-defined rules to detect potential attacks. As the size of an organization grows and new types of intrusions appear, the quantity and complexity of the rules also increase. Moreover, IDPSs generate an overwhelming number of logs that are challenging to handle and analyze. For a more effective and integrative analysis and management of the rules and logs, we propose a novel visual analytics tool, Hyperion. Hyperion interactively visualizes rules to help users understand how the IDPS rules are managed and applied to the enterprise's network entities. Hyperion also provides effective visualizations to enable users to visually analyze the type, period, traffic, and frequency of attacks in addition to a traditional count-based timeline visualization. Finally, Hyperion enables users to interactively simulate the effect of a change in parameters of a detection rule. These features can help streamline the security control cycle consisting of rule application, information collection, log analysis, and rule revision.
Author supplied keywords
Cite
CITATION STYLE
Yoo, S., Jo, J., Kim, B., & Seo, J. (2020). Hyperion: A Visual Analytics Tool for an Intrusion Detection and Prevention System. IEEE Access, 8, 133865–133881. https://doi.org/10.1109/ACCESS.2020.3010789
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.