Interactive Analysis of NetFlows for Misuse Detection in Large IP Networks
Florian Mansmann, Fabian Fischer, Daniel A. Keim, Stephan Pietzko, Marcel Waldvogel · KOPS (University of Konstanz) · 2009
While more and more applications require higher network bandwidth, there is al-so a tendency that large portions of!his bandwidth are misused for dubious purposes, such as unauthorized VoIP, file sharing, or criminal hotnet activity. Automatie intru-sion detection methods can detcct a large portion 01 ' such misuse, but novel patterns can only bc detected by humans. Moreover, interpretation of large amouots of alerts imposes new challenges on the analysts. The goal of this paper is to preseot the vi-sual analysis systcm NFlowVis to intcractively detcct unwanted usage of the network infrastructure either by pivoting NetFlows using lOS a1erts or by spccifying usage pat-terns. such as sets of suspicious port numbers. Thereby, our work focuses on providing a scalable approach to store and retrieve largc quantities of NetAows by means of a database management system. 1