A Network Visualization System for Anomaly Detection and Attack Tracing.

Xin Fan,Wenjie Luo,Xiaoju Dong,Rui Su
DOI: https://doi.org/10.1007/978-981-13-2203-7_45
2018-01-01
Abstract:Analyzing network data is one of the important means to safeguard network security. However, how to detect anomalies and trace back the origin of attacks in the enlarging scale of network data is still a challenge now. This paper designs and implements a network visualization system, which meets three main requirements: the situation awareness of the whole network, the rapid detection of anomalies, and the track of attack source. To combine multiple visualization technologies reasonably, the system provides information from three levels. It also uses unsupervised learning methods to detect anomalies in different ways. Therefore, the system enhances the ability of identifying abnormal behaviors from network data. Its efficiency is tested by the usage of data in the ChinaVis 2016.
What problem does this paper attempt to address?