Monitoring large IP spaces with ClockView

dc.contributor.authorKintzel, Christopher
dc.contributor.authorFuchs, Johannes
dc.contributor.authorMansmann, Florian
dc.date.accessioned2012-03-20T09:55:47Zdeu
dc.date.available2012-03-20T09:55:47Zdeu
dc.date.issued2011
dc.description.abstractThe growing amounts of hosts that are placed into the networks represent an enormous challenge to most network administrators who have to monitor these hosts conscientiously. While automatically monitoring the network for slow or failing components has become common practice, defining an acceptable state of the system is only possible to a very limited extent and thus exploratory analysis tasks by real human analysts complement the analysis process. However, this is a problem of scale since it is infeasible to manually inspect thousands of hosts without proper visual support for the tasks of gaining an overview, focusing and retrieving details on demand. In this paper we present a design study to enable visual support for monitoring large IP spaces. In particular, the presented system features 1) a scalable glyph representation in the style of a clock for giving an overview of the activity over time of thousands of hosts in the network, 2) subnet and port views for focusing the analysis to a particular subset of the data and 3) detailed pixel matrix visualizations for interpreting concrete traffic patterns. Furthermore, the tool's feedback loop, which is implemented through interaction capabilities, allows for retrieving new details, refocusing and enhancing of the overview.eng
dc.description.versionpublished
dc.identifier.citationFirst publ. in: VizSec '11 2011 International Symposium on Visualization for Cyber Security : Pittsburgh, PA, USA — July 20 - 20, 2011. - ACM : New York, NY, 2011. - Article No. 2. - ISBN: 978-1-4503-0679-9deu
dc.identifier.doi10.1145/2016904.2016906deu
dc.identifier.ppn362165793deu
dc.identifier.urihttp://kops.uni-konstanz.de/handle/123456789/18654
dc.language.isoengdeu
dc.legacy.dateIssued2012-03-20deu
dc.rightsterms-of-usedeu
dc.rights.urihttps://rightsstatements.org/page/InC/1.0/deu
dc.subjectNetwork securitydeu
dc.subjectpattern detectiondeu
dc.subject.ddc004deu
dc.titleMonitoring large IP spaces with ClockVieweng
dc.typeINPROCEEDINGSdeu
dspace.entity.typePublication
kops.citation.bibtex
@inproceedings{Kintzel2011Monit-18654,
  year={2011},
  doi={10.1145/2016904.2016906},
  title={Monitoring large IP spaces with ClockView},
  isbn={978-1-4503-0679-9},
  publisher={ACM Press},
  address={New York, New York, USA},
  booktitle={Proceedings of the 8th International Symposium on Visualization for Cyber Security - VizSec '11},
  pages={1--10},
  author={Kintzel, Christopher and Fuchs, Johannes and Mansmann, Florian}
}
kops.citation.iso690KINTZEL, Christopher, Johannes FUCHS, Florian MANSMANN, 2011. Monitoring large IP spaces with ClockView. the 8th International Symposium. Pittsburgh, Pennsylvania, 20. Juli 2011 - 20. Juli 2011. In: Proceedings of the 8th International Symposium on Visualization for Cyber Security - VizSec '11. New York, New York, USA: ACM Press, 2011, pp. 1-10. ISBN 978-1-4503-0679-9. Available under: doi: 10.1145/2016904.2016906deu
kops.citation.iso690KINTZEL, Christopher, Johannes FUCHS, Florian MANSMANN, 2011. Monitoring large IP spaces with ClockView. the 8th International Symposium. Pittsburgh, Pennsylvania, Jul 20, 2011 - Jul 20, 2011. In: Proceedings of the 8th International Symposium on Visualization for Cyber Security - VizSec '11. New York, New York, USA: ACM Press, 2011, pp. 1-10. ISBN 978-1-4503-0679-9. Available under: doi: 10.1145/2016904.2016906eng
kops.citation.rdf
<rdf:RDF
    xmlns:dcterms="http://purl.org/dc/terms/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:bibo="http://purl.org/ontology/bibo/"
    xmlns:dspace="http://digital-repositories.org/ontologies/dspace/0.1.0#"
    xmlns:foaf="http://xmlns.com/foaf/0.1/"
    xmlns:void="http://rdfs.org/ns/void#"
    xmlns:xsd="http://www.w3.org/2001/XMLSchema#" > 
  <rdf:Description rdf:about="https://kops.uni-konstanz.de/server/rdf/resource/123456789/18654">
    <void:sparqlEndpoint rdf:resource="http://localhost/fuseki/dspace/sparql"/>
    <bibo:uri rdf:resource="http://kops.uni-konstanz.de/handle/123456789/18654"/>
    <dc:contributor>Kintzel, Christopher</dc:contributor>
    <dcterms:rights rdf:resource="https://rightsstatements.org/page/InC/1.0/"/>
    <dcterms:bibliographicCitation>First publ. in: VizSec '11 2011 International Symposium on Visualization for Cyber Security : Pittsburgh, PA, USA — July 20 - 20, 2011. -  ACM : New York, NY, 2011. - Article No. 2. - ISBN: 978-1-4503-0679-9</dcterms:bibliographicCitation>
    <dcterms:available rdf:datatype="http://www.w3.org/2001/XMLSchema#dateTime">2012-03-20T09:55:47Z</dcterms:available>
    <foaf:homepage rdf:resource="http://localhost:8080/"/>
    <dc:contributor>Mansmann, Florian</dc:contributor>
    <dc:rights>terms-of-use</dc:rights>
    <dc:date rdf:datatype="http://www.w3.org/2001/XMLSchema#dateTime">2012-03-20T09:55:47Z</dc:date>
    <dcterms:abstract xml:lang="eng">The growing amounts of hosts that are placed into the networks represent an enormous challenge to most network administrators who have to monitor these hosts conscientiously. While automatically monitoring the network for slow or failing components has become common practice, defining an acceptable state of the system is only possible to a very limited extent and thus exploratory analysis tasks by real human analysts complement the analysis process. However, this is a problem of scale since it is infeasible to manually inspect thousands of hosts without proper visual support for the tasks of gaining an overview, focusing and retrieving details on demand. In this paper we present a design study to enable visual support for monitoring large IP spaces. In particular, the presented system features 1) a scalable glyph representation in the style of a clock for giving an overview of the activity over time of thousands of hosts in the network, 2) subnet and port views for focusing the analysis to a particular subset of the data and 3) detailed pixel matrix visualizations for interpreting concrete traffic patterns. Furthermore, the tool's feedback loop, which is implemented through interaction capabilities, allows for retrieving new details, refocusing and enhancing of the overview.</dcterms:abstract>
    <dc:contributor>Fuchs, Johannes</dc:contributor>
    <dc:creator>Mansmann, Florian</dc:creator>
    <dcterms:title>Monitoring large IP spaces with ClockView</dcterms:title>
    <dcterms:issued>2011</dcterms:issued>
    <dspace:isPartOfCollection rdf:resource="https://kops.uni-konstanz.de/server/rdf/resource/123456789/36"/>
    <dcterms:hasPart rdf:resource="https://kops.uni-konstanz.de/bitstream/123456789/18654/2/Keim_Monitoring.pdf"/>
    <dc:creator>Fuchs, Johannes</dc:creator>
    <dc:creator>Kintzel, Christopher</dc:creator>
    <dspace:hasBitstream rdf:resource="https://kops.uni-konstanz.de/bitstream/123456789/18654/2/Keim_Monitoring.pdf"/>
    <dc:language>eng</dc:language>
    <dcterms:isPartOf rdf:resource="https://kops.uni-konstanz.de/server/rdf/resource/123456789/36"/>
  </rdf:Description>
</rdf:RDF>
kops.conferencefieldthe 8th International Symposium, 20. Juli 2011 - 20. Juli 2011, Pittsburgh, Pennsylvaniadeu
kops.date.conferenceEnd2011-07-20
kops.date.conferenceStart2011-07-20
kops.description.openAccessopenaccessgreen
kops.flag.knbibliographytrue
kops.identifier.nbnurn:nbn:de:bsz:352-186545deu
kops.location.conferencePittsburgh, Pennsylvania
kops.sourcefield<i>Proceedings of the 8th International Symposium on Visualization for Cyber Security - VizSec '11</i>. New York, New York, USA: ACM Press, 2011, pp. 1-10. ISBN 978-1-4503-0679-9. Available under: doi: 10.1145/2016904.2016906deu
kops.sourcefield.plainProceedings of the 8th International Symposium on Visualization for Cyber Security - VizSec '11. New York, New York, USA: ACM Press, 2011, pp. 1-10. ISBN 978-1-4503-0679-9. Available under: doi: 10.1145/2016904.2016906deu
kops.sourcefield.plainProceedings of the 8th International Symposium on Visualization for Cyber Security - VizSec '11. New York, New York, USA: ACM Press, 2011, pp. 1-10. ISBN 978-1-4503-0679-9. Available under: doi: 10.1145/2016904.2016906eng
kops.submitter.emailoleg.kozlov@uni-konstanz.dedeu
kops.title.conferencethe 8th International Symposium
relation.isAuthorOfPublication7c667307-a568-40d9-912f-6bdbf1b0ef79
relation.isAuthorOfPublication6dc854f5-8120-4da2-9c7a-c42f860f77fc
relation.isAuthorOfPublication90244953-4003-4a15-ae6e-0b9d164ea2a3
relation.isAuthorOfPublication.latestForDiscovery7c667307-a568-40d9-912f-6bdbf1b0ef79
source.bibliographicInfo.fromPage1
source.bibliographicInfo.toPage10
source.identifier.isbn978-1-4503-0679-9
source.publisherACM Press
source.publisher.locationNew York, New York, USA
source.titleProceedings of the 8th International Symposium on Visualization for Cyber Security - VizSec '11

Dateien

Originalbündel

Gerade angezeigt 1 - 1 von 1
Vorschaubild nicht verfügbar
Name:
Keim_Monitoring.pdf
Größe:
5.84 MB
Format:
Adobe Portable Document Format
Keim_Monitoring.pdf
Keim_Monitoring.pdfGröße: 5.84 MBDownloads: 969

Lizenzbündel

Gerade angezeigt 1 - 1 von 1
Vorschaubild nicht verfügbar
Name:
license.txt
Größe:
1.92 KB
Format:
Plain Text
Beschreibung:
license.txt
license.txtGröße: 1.92 KBDownloads: 0