NetFlow Data Visualization Based on Graphs

  • Authors:
  • Pavel Minarik;Tomas Dymacek

  • Affiliations:
  • Institute of Computer Science, Masaryk University, Brno, Czech Republic 602 00;Mycroft Mind, Inc., Brno, Czech Republic 602 00

  • Venue:
  • VizSec '08 Proceedings of the 5th international workshop on Visualization for Computer Security
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

We present an innovative approach to NetFlow data processing and visualization developed at Masaryk University in Brno. Our visualization method based on graphs bridges the gap between highly aggregated information visualization represented by charts and too much detailed information represented by the log files. In our visualization method the graph nodes stand for network devices and oriented edges represent communication between these devices. We also present the utilization of external data sources (DNS, port names, etc.), which helps to present NetFlow data in more intuitive way. Hence this approach is very natural one for both network administrators and non-specialists. Based on these methods a proof-of-concept tool called NetFlow Visualizerhas been developed and is now offered as an plug-in for the NetFlow probes.