Visible to the public IDSPlanet: A Novel Radial Visualization of Intrusion Detection Alerts

TitleIDSPlanet: A Novel Radial Visualization of Intrusion Detection Alerts
Publication TypeConference Paper
Year of Publication2016
AuthorsShi, Yang, Zhang, Yaoxue, Zhou, Fangfang, Zhao, Ying, Wang, Guojun, Shi, Ronghua, Liang, Xing
Conference NameProceedings of the 9th International Symposium on Visual Information Communication and Interaction
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4149-3
Keywordscomposability, cyber security, IDS, pubcrawl, visualization
Abstract

In this article, we present a novel radial visualization of IDS alerts, named IDSPlanet, which helps administrators identify false positives, analyze attack patterns, and understand evolving network conditions. Inspired by celestial bodies, IDSPlanet is composed of Chrono Rings, Alert Continents, and Interactive Core. These components correspond with temporal features of alert types, patterns of behavior in affected hosts, and correlations amongst alert types, attackers and targets. The visualization provides an informative picture for the status of the network. In addition, IDSPlanet offers different interactions and monitoring modes, which allow users to interact with high-interest individuals in detail as well as to explore overall pattern.

URLhttp://doi.acm.org/10.1145/2968220.2968221
DOI10.1145/2968220.2968221
Citation Keyshi_idsplanet:_2016