This paper describes our work to develop an environment and novel visualization techniques for the visual representation, exploration, and analysis of network traffic data to ease the identification and analysis of sophisticated attacks above and beyond the ability for traditional network firewalls to detect and block. The visualization techniques are geared towards aiding analysts in filtering unwanted or unneeded data in favor of data deemed more critical and more representative of the sophisticated attacks the analysts must focus their attention on. The environment provides the needed capabilities for analyzing traditional network traffic data without additional filtering, i.e., the environment itself provides the needed capabilities
Index Terms:
Visualization, Intrusion Detection,Graphical User Interfaces
Citation:
Robert F. Erbacher, Kim Christensen, Amanda Sundberg, "Designing Visualization Capabilities for IDS Challenges," vizsec, pp.15, IEEE Workshops on Visualization for Computer Security (VizSec'05), 2005