FIRST - Improving Security Together 18th Annual FIRST Conference - June 2006 - Baltimore, Maryland

VisFlowConnect-IP: A Link-Based Visualization of NetFlows for Security Monitoring

Platinum Sponsor


Silver Sponsor


Local Host

CERT Coordination Center

Supporting Sponsors






Korea CertCC

Conference Schedule

18th Annual FIRST Conference

Friday – June 30th, 11:45

Network traffic dynamics have become an important behavior-based approach to assist security administrators in protecting networks. In this paper/presentation we present VisFlowConnect-IP, a link-based network flow visualization tool that allows operators to detect and investigate anomalous internal and external network traffic. We model the network as a graph with hosts being nodes and traffic flows being edges. We present a detailed description of VisFlowConnect-IP functionality and demonstrate its application to traffic dynamics in order to monitor, discover, and investigate security-relevant events.

Authors & presenters

  • USWilliam Yurcik Presenter (NCSA-IRST – National Center for Supercomputing Applications, US)

Conference Schedule