3D Graph Visualisation of Web Normal and Malicious Traffic

  • Authors:
  • I. Xydas;G. Miaoulis;P.-F. Bonnefoi;D. Plemenos;D. Ghazanfarpour

  • Affiliations:
  • Technological Educational Institute of Athens, Ag.Spiridona St., 12210 Athens, Greece;Technological Educational Institute of Athens, Ag.Spiridona St., 12210 Athens, Greece;University of Limoges, XLIM Laboratory, CNRS, UMR, France;University of Limoges, XLIM Laboratory, CNRS, UMR, France;University of Limoges, XLIM Laboratory, CNRS, UMR, France

  • Venue:
  • IV '06 Proceedings of the conference on Information Visualization
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Once a web site has been made operational by a company, organisation or individual there is a wish to know the details regarding the connections to the site. In addition, there is a great interest to monitor the activity profile of the web site in terms of how many hits are received, where they come from, the relationship between this activity and increased revenues of the business and so on. Due to the complexity and volume of data involved in these tasks the only way to manage all of the information is to present it using a visual paradigm. Furthermore, web sites are likely to be regularly scanned and attacked by both automated and manual means. Companies, organisations and individuals are making every effort to build and maintain secure web sites. In this paper we will present an ongoing surveillance prototype system which offers a visual aid to the web analyst by monitoring and exploring 3D graphs. The system offers a visual surveillance of the web traffic for both normal and malicious activity. Web requests are presented as 3D directed graphs. Colours are used on the 3D graphics to indicate malicious attempts or anomalous traffic and the analyst has the ability to perform visual data analysis by navigating online into the web request payload, of either normal or malicious traffic.