Tool update: high alarm count issues in IDS rainstorm

  • Authors:
  • Kulsoom Abdullah;John A. Copeland

  • Affiliations:
  • Georgia Institute of Technology;Georgia Institute of Technology

  • Venue:
  • Proceedings of the 3rd international workshop on Visualization for computer security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

We developed a tool to help network administrators deal with the large amount of alarms generated from network security appliances. It efficiently uses screen space representing a high number of IP addresses along with time sequence so that general alarm activity for a network can be visualized along with details, if desired. The tool was useful but encountered problems when there was a significant increase in the amount of alarms. The issues that resulted are addressed in this paper along with methods to ease them.