Backhoe, a Packet Trace and Log Browser

  • Authors:
  • Sergey Bratus;Axel Hansen;Fabio Pellacini;Anna Shubina

  • Affiliations:
  • Dartmouth College, USA NH 03755;Dartmouth College, USA NH 03755;Dartmouth College, USA NH 03755;Dartmouth College, USA NH 03755

  • Venue:
  • VizSec '08 Proceedings of the 5th international workshop on Visualization for Computer Security
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

We present Backhoe, a tool for browsing packet trace or other event logs that makes it easy to spot "statistical novelties" in the traffic, i.e. changes in the character of frequency distributions of feature values and in mutual relationships between pairs of features. Our visualization uses feature entropy and mutual information displays as either the top-level summary of the dataset or alongside the data. Our tool makes it easy to switch between absolute and conditional metrics, and observe their variations at a glance. We successfully used Backhoefor analysis of proprietary protocols.