Interactive Visual Classification and Analysis on Network Activity

Siming Chen,Xiaoru Yuan
2015-01-01
Abstract:Monitoring the behavior of hosts and identifying anomaly situation in the streaming network is critical but challenging. There lacks of efficient methods to quickly identify and classified the different behavior for IPs and ports in a dynamic scenario. In this work, we propose a visual analytics approach for quickly identifying anomaly situation and tracking the behavior of interested IP/ports from the streaming network flow data. We build up an interactive visual classification and analysis system, providing filtering and sorting methods, as well as correlation exploration. Features can be classified through interactive brushing and be monitored in other analysis stage. Our case study turns our method can efficiently identify anomaly events from the complex global network flow data.
What problem does this paper attempt to address?