FIRST - Improving Security Together 18th Annual FIRST Conference - June 2006 - Baltimore, Maryland

VisFlowConnect-IP: A Link-Based Visualization of NetFlows for Security Monitoring







Platinum Sponsor

BT



Silver Sponsor

Diageo



Local Host

CERT Coordination Center



Supporting Sponsors

Sun



Google



Hitachi



ISS



E-Secure-IT

Korea CertCC



Conference Schedule

18th Annual FIRST Conference

Friday – June 30th, 11:45

Network traffic dynamics have become an important behavior-based approach to assist security administrators in protecting networks. In this paper/presentation we present VisFlowConnect-IP, a link-based network flow visualization tool that allows operators to detect and investigate anomalous internal and external network traffic. We model the network as a graph with hosts being nodes and traffic flows being edges. We present a detailed description of VisFlowConnect-IP functionality and demonstrate its application to traffic dynamics in order to monitor, discover, and investigate security-relevant events.

Authors & presenters

  • USWilliam Yurcik  Presenter (NCSA-IRST – National Center for Supercomputing Applications, US)


 
Conference Schedule