Existence Plots: A Low-Resolution Time Series for Port Behavior Analysis

  • Authors:
  • Jeff Janies

  • Affiliations:
  • CERT Network Situational Awareness Group, Pittsburgh PA 15213

  • Venue:
  • VizSec '08 Proceedings of the 5th international workshop on Visualization for Computer Security
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

An existence plot is a low-resolution visualization that concurrently represents the activity of all 216ports on a single host. By doing so, we are able to show patterns of port usage which can indicate server activity and demonstrate scanning. In this work we introduce the existence plot as a visualization and discuss its use in gaining insight into a host's behavior.