A Visualization System for Multiple Heterogeneous Network Security Data and Fusion Analysis

A Visualization System for Multiple Heterogeneous Network Security Data and Fusion Analysis
复制标题

DOI:
10.3837/tiis.2016.06.019
复制
发表时间:
2016-06
期刊:
KSII Trans. Internet Inf. Syst.
影响因子:
--
通讯作者:
Shenmin Zhang;Ronghua Shi;Jue Zhao
Shenmin Zhang;Ronghua Shi;Jue Zhao
中科院分区:
其他
文献类型:
--
作者:
Shenmin Zhang;Ronghua Shi;Jue Zhao

文献摘要

相似文献

传统方法由于可扩展性低、对大数据的支持能力弱、数据协同分析能力不足、态势感知能力不足等问题,已不能满足安全数据分析的需求。本文提出了融合多源安全数据和掌握网络状况的可视化方法。首先,对数据源在其收集位置进行分类,安全数据的对象从三个不同的层取。其次,采用热图显示主机状态;Treemap用于可视化Netflow日志;采用径向节点-链路图表示IPS日志。最后,提出标记树图进行数据级融合,提取时间序列特征进行特征级融合。通过与获奖作品的对比分析,证明该方法对于网络分析人员便于数据特征融合,以统一、便捷、准确的模式更好地了解网络安全状况具有很大的优势。
Owing to their low scalability, weak support on big data, insufficient data collaborative analysis and inadequate situational awareness, the traditional methods fail to meet the needs of the security data analysis. This paper proposes visualization methods to fuse the multi-source security data and grasp the network situation. Firstly, data sources are classified at their collection positions, with the objects of security data taken from three different layers. Secondly, the Heatmap is adopted to show host status; the Treemap is used to visualize Netflow logs; and the radial Node-link diagram is employed to express IPS logs. Finally, the Labeled Treemap is invented to make a fusion at data-level and the Time-series features are extracted to fuse data at feature-level. The comparative analyses with the prize-winning works prove this method enjoying substantial advantages for network analysts to facilitate data feature fusion, better understand network security situation with a unified, convenient and accurate mode.