Flowtag: a collaborative attack-analysis, reporting, and sharing tool for security researchers
Flowtag: a collaborative attack-analysis, reporting, and sharing tool for security researchers
复制标题
Flowtag:面向安全研究人员的协作攻击分析、报告和共享工具
DOI:
--
复制
发表时间:
2006
期刊:
影响因子:
--
通讯作者:
J. Copeland
中科院分区:
文献类型:
--
作者:
Christopher P. Lee;J. Copeland
Current tools for forensic analysis require many hours to understand novel attacks, causing reports to be terse and untimely. We apply visual filtering and tagging of flows in a novel way to address the current limitations of post-attack analysis, reporting, and sharing. We discuss the benefits of visual filtering and tagging of network flows and introduce FlowTag as our prototype tool for Honeynet researchers. We argue that online collaborative analysis benefits security researchers by organizing attacks, collaborating on analysis, forming attack databases for trend analysis, and in promoting new security research areas. Lastly, we show three attacks on the Georgia Tech Honeynet and describe the analysis process using FlowTag.