IDSRadar: a real-time visualization framework for IDS alerts

被引:0
作者
Ying Zhao
FangFang Zhou
XiaoPing Fan
Xing Liang
YongGang Liu
机构
[1] Central South University,Information Science and Engineering School
[2] Hunan University of Finance & Economics,Laboratory of Networked Systems
来源
Science China Information Sciences | 2013年 / 56卷
关键词
visual analytics; information visualization; cyber security; IDS log; entropy;
D O I
暂无
中图分类号
学科分类号
摘要
Intrusion Detection Systems (IDS) is an automated cyber security monitoring system to sense malicious activities. Unfortunately, IDS often generates both a considerable number of alerts and false positives in IDS logs. Information visualization allows users to discover and analyze large amounts of information through visual exploration and interaction efficiently. Even with the aid of visualization, identifying the attack patterns and recognizing the false positives from a great number of alerts are still challenges. In this paper, a novel visualization framework, IDSRadar, is proposed for IDS alerts, which can monitor the network and perceive the overall view of the security situation by using radial graph in real-time. IDSRadar utilizes five categories of entropy functions to quantitatively analyze the irregular behavioral patterns, and synthesizes interactions, filtering and drill-down to detect the potential intrusions. In conclusion, IDSRadar is used to analyze the mini-challenges of the VAST challenge 2011 and 2012.
引用
收藏
页码:1 / 12
页数:11
相关论文
共 50 条
[21]   Real-time vehicle tracking on a highway [J].
Hsu, WL ;
Tyan, HR ;
Liang, YM ;
Jeng, BS ;
Fan, KC .
JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2005, 21 (04) :733-752
[22]   Transpacific Testbed for Real-Time Experimentation [J].
Ajayi, Oluwaseyi ;
Huseynov, Huseyn ;
Saadawi, Tarek ;
Tsuru, Masato ;
Kourai, Kenichi .
2021 IEEE 4TH 5G WORLD FORUM (5GWF 2021), 2021, :505-510
[23]   Reliable Real-time Destination Prediction [J].
Meyers, Gregory ;
Martinez-Garcia, Miguel ;
Zhang, Yu ;
Zhang, Yudong .
2021 IEEE 19TH INTERNATIONAL CONFERENCE ON INDUSTRIAL INFORMATICS (INDIN), 2021,
[24]   A Generalized Stealth Attack Localization Framework for Smart Grid Network Under Real-Time Test Environment [J].
Jena, Prasanta Kumar ;
Palahalli, Harshavardhan ;
Koley, Ebha ;
Ghosh, Subhojit .
IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2025,
[25]   Effect of data time interval on real-time flood forecasting [J].
Remesan, Renji ;
Ahmadi, Azadeh ;
Shamim, Muhammad Ali ;
Han, Dawei .
JOURNAL OF HYDROINFORMATICS, 2010, 12 (04) :396-407
[26]   Security analytics for real-time forecasting of cyberattacks [J].
Javed, Amir ;
Lakoju, Mike ;
Burnap, Pete ;
Rana, Omer .
SOFTWARE-PRACTICE & EXPERIENCE, 2022, 52 (03) :788-804
[27]   Real-Time Visual Analytics for Text Streams [J].
Keim, Daniel A. ;
Krstajic, Milos ;
Rohrdantz, Christian ;
Schreck, Tobias .
COMPUTER, 2013, 46 (07) :47-55
[28]   A multi-objective reinforcement learning framework for real-time drilling optimization based on symbolic regression and perception [J].
Song, Zehua ;
Song, Yu ;
Yang, Jin ;
Liu, Baosheng ;
Gao, Bingzhen ;
Tang, Jizhou .
GEOENERGY SCIENCE AND ENGINEERING, 2025, 244
[29]   Real-Time Monitoring With Timing Side Information [J].
Yu, Siyuan ;
Chen, Wei ;
Poor, H. Vincent .
IEEE TRANSACTIONS ON COMMUNICATIONS, 2023, 71 (04) :1953-1969
[30]   Private and Fresh Real-Time Status Updating [J].
Seo, Hyowoon ;
Lee, Hojung ;
Son, Kyungrak ;
Choi, Wan .
IEEE COMMUNICATIONS LETTERS, 2022, 26 (02) :239-243