Visual Correlation of Network Alerts

  • Authors:
  • Stefano Foresti;James Agutter;Yarden Livnat;Shaun Moon;Robert Erbacher

  • Affiliations:
  • University of Utah;University of Utah;University of Utah;University of Utah;Utah State University

  • Venue:
  • IEEE Computer Graphics and Applications
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

This article presents VisAlert, a novel visual correlation tool that displays network--and host-based alerts from disparate sensors. The approach is based on the fundamental premise that an alert must possess three attributes: what, when, and where. These attributes provide a vehicle for comparing seemingly disparate events. VisAlert facilitates and promotes situational awareness in complex network environments by providing the user with a holistic view of network security to aid in the detection of sophisticated and malicious activities. This visualization was developed with a user centered, interdisciplinary design methodology using domain analysis, visual design, user feedback, and software implementation. Network analysts and decision makers with experience in large organizational networks were involved in the iterative development process. VisAlert was deployed at the Air Force Research Lab where it generated a positive response due to its intuitiveness, effectiveness, simplicity, and flexibility, features that enhance the capability of network analysts to detect, diagnose, and respond to difficult to detect anomalies.