loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
IEEE Workshops on Visualization for Computer Security (VizSec'05)
Exploring Three-dimensional Visualization for Intrusion Detection
Minneapolis, Minnesota
October 26-October 26
ISBN: 0-7803-9477-1
Adam Oline, Iowa State University
Dirk Reiners, Iowa State University
Intrusion detection systems have been popular tools in the battle against adversaries who, for whatever reason, desire to break into networks, compromise hosts, and steal valuable information. One problem with current implementations, however, is the sheer number of alerts they can generate, many of which tend to be false alarms. This drawback makes effective use of such systems a challenging task. In this paper we explore three-dimensional approaches to visualizing network intrusion detection system alerts and aggregated network statistics in order to provide the system administrator with a better picture of the events occurring on his or her network. While some research has been done using twodimensional concepts, 3D approaches have not received much attention with regard to detecting network intrusions. Evaluation of our visualizations using the 1999 DARPA Intrusion Detection Evaluation data set demonstrates the potential benefit of utilizing the third dimension. We show how a number of attack types in the data set generate visual evidence of abnormal activity that a security administrator might use as motivation for further investigation.
Index Terms:
intrusion detection, visualization, data reduction, three-dimensional
Citation:
Adam Oline, Dirk Reiners, "Exploring Three-dimensional Visualization for Intrusion Detection," vizsec, pp.14, IEEE Workshops on Visualization for Computer Security (VizSec'05), 2005
Usage of this product signifies your acceptance of the Terms of Use.