A visualization tool for exploring multi-scale network traffic anomalies

  • Authors:
  • Romain Fontugne;Toshio Hirotsu;Kensuke Fukuda

  • Affiliations:
  • The Graduate University for Advanced Studies, Tokyo, Japan;Hosei University, Tokyo, Japan;National Institute of Informatics, PRESTO and JST, Tokyo, Japan

  • Venue:
  • SPECTS'09 Proceedings of the 12th international conference on Symposium on Performance Evaluation of Computer & Telecommunication Systems
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Visualization is an intuitive and powerful way of understanding the evolution of huge amounts of network traffic in terms of characterizing network anomalies. We propose an interactive tool to display, explore, and understand network traffic focusing on anomalies. It displays traffic on different temporal and spatial (address and port) scales and lets users navigate network data by using a simple interface. Different graphical representations are used to highlight anomalies quickly, and textual packet information about corresponding plotted points are provided. The proposed tool provides good support for understanding traffic behavior and for evaluating the effectiveness of anomaly detection method. The tool directly reads dump files and uses no intermediate database in daily operations. This paper demonstrates several examples emphasizing specific patterns for various anomalies.