Anton Chuvakin points to this funny link about visualization. Especially the statement:
"Chart-based encryption -- data goes in, no information comes out" is funny. This is worth keeping in mind when thinking about what to visualize in a security setting. In my work we want to visualize potential intrusion activities and attacks at a network level. We want to give the user a situational picture ("Lägesbild " in Swedish) of the activities at different nodes in the network. In order to do that, we have to use visualization to communicate in an understandable way.
Showing posts with label data mining. Show all posts
Showing posts with label data mining. Show all posts
Monday, June 25, 2007
Visualization
Labels:
blog entry,
data mining,
intrusion detection,
visualization
Monday, February 26, 2007
Paper 1: A Framework For The Application Of Association Rule Mining In Large Intrusion Detection Infrastructures
This paper is about using data mining in form of association rules to extract rules describing correlations between alarms from a large set of intrusion detection systems. The rules can then be used as basis for creating new rules to detect correlated intrusions.
Since the system mines for correlations between a huge amount of alarms it needs some form of data filtering. As filtering approach, the system uses graph algorithms with a graph where IP addresses are vertices and detected alarms are edges, drawn from source to destination IP addresses. Only connected components of the graph are used for mining.
Amongst the most interesting things in this article are the following:
Since the system mines for correlations between a huge amount of alarms it needs some form of data filtering. As filtering approach, the system uses graph algorithms with a graph where IP addresses are vertices and detected alarms are edges, drawn from source to destination IP addresses. Only connected components of the graph are used for mining.
Amongst the most interesting things in this article are the following:
- The number of rules generated each day can be used to detect weired (anomalous) network activites.
- This can also be done for each subnet of the network and thus find high risk networks.
Subscribe to:
Posts (Atom)
