A novel visualization approach for efficient network-wide traffic monitoring

  • Taghrid Samak*
  • , Adel El-Atawy
  • , Ehab Al-Shaer
  • , Mohamed Ismail
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

5 Scopus citations

Abstract

Network traffic visualization provides very effective means for monitoring anomalous activities as well as detecting large scale network attacks. This work proposes a novel and flexible technique for representing traffic activities that reside in network flows and their patterns. The technique utilizes a set of different Space-Filling Curves (SFC) to map the collected statistics to images that emphasize traffic patterns. Our approach to use the enhanced locality of SFC clustering property makes anomalies such as large scale DDoS attacks and scanning activities easily identifiable, compared to other traditional techniques. Also, widely dispersed communication patterns are rendered easier to understand using our proposed traffic-to-image mappings. This new representation preserves traffic properties leading to more accurate and robust anomaly detection even if aggressive compression is performed on the resulting images. In addition, using our proposed technique, the relation between multiple packet fields can be easily obtained to analyze correlated attacks.

Original languageEnglish
Title of host publicationFifth IEEE/IFIP Workshop on End-to-End Monitoring Techniques and Services, E2EMON'07
DOIs
StatePublished - 2007
Externally publishedYes
Event5th IEEE/IFIP Workshop on End-to-End Monitoring Techniques and Services, E2EMON'07 - Munich, Germany
Duration: 21 May 200721 May 2007

Publication series

NameFifth IEEE/IFIP Workshop on End-to-End Monitoring Techniques and Services, E2EMON'07

Conference

Conference5th IEEE/IFIP Workshop on End-to-End Monitoring Techniques and Services, E2EMON'07
Country/TerritoryGermany
CityMunich
Period21/05/0721/05/07

ASJC Scopus subject areas

  • Computer Science Applications
  • Hardware and Architecture
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'A novel visualization approach for efficient network-wide traffic monitoring'. Together they form a unique fingerprint.

Cite this