Flowtag: a collaborative attack-analysis, reporting, and sharing tool for security researchers

Flowtag: a collaborative attack-analysis, reporting, and sharing tool for security researchers
复制标题

Flowtag:面向安全研究人员的协作攻击分析、报告和共享工具

DOI:
--
复制
发表时间:
2006
期刊:
Visualization for Computer Security
影响因子:
--
通讯作者:
J. Copeland
J. Copeland
中科院分区:
--
文献类型:
--
作者:
Christopher P. Lee;J. Copeland

文献摘要

被引文献

相似文献

目前的法医分析工具需要花费很多时间来理解新的攻击,导致报告简洁而不及时。我们以一种新颖的方式应用视觉过滤和标记流,以解决当前攻击后分析,报告和共享的局限性。我们讨论了视觉过滤和标记的网络流的好处,并介绍FlowTag作为我们的原型工具的蜜网研究人员。我们认为,在线协作分析有利于安全研究人员组织攻击,合作分析,形成攻击数据库的趋势分析,并在促进新的安全研究领域。最后,我们展示了三个攻击格鲁吉亚技术蜜网,并描述了使用FlowTag的分析过程。
Current tools for forensic analysis require many hours to understand novel attacks, causing reports to be terse and untimely. We apply visual filtering and tagging of flows in a novel way to address the current limitations of post-attack analysis, reporting, and sharing. We discuss the benefits of visual filtering and tagging of network flows and introduce FlowTag as our prototype tool for Honeynet researchers. We argue that online collaborative analysis benefits security researchers by organizing attacks, collaborating on analysis, forming attack databases for trend analysis, and in promoting new security research areas. Lastly, we show three attacks on the Georgia Tech Honeynet and describe the analysis process using FlowTag.