FloVis: Leveraging Visualization to Protect Sensitive Network Infrastructure
Joel Glanfield, Diana Paterson, Christopher D. Smith, Teryl Taylor, Stephen Brooks, Carrie E. Gates, John McHugh · 2009
Computer networks have become critical to NATO operations. Much of NATO's computer traffic runs over civilian networks, and NATO computers are accessible to a wide variety of malicious activities. The scale of the network traffic involved makes monitoring and analysis difficult, and the rapid deployment of computer systems to new areas places additional stresses on operators and analysts. We have developed an extensible suite of visualization tools, FloVis, to aid system administrators and system security officers in understanding the traffic that passes over their networks. The suite is useful for both defensive purposes as well as for evaluating and understanding the effects of offensive information operations. This paper describes FloVis and provides examples of its capabilities. FloVis is a visualization framework that was built with the aim of providing the necessary machinery to allow security analysts to leverage the benefits of data visualization while attempting to detect malicious network behavior (Taylor et al., 2009). This is accomplished not only by providing new and interesting visualizations, but by allowing these visualizations to synergize their unique perspectives to provide further insight into network data. FloVis was developed to promote: 1. Extensibility: The integration of additional visualizations is seamless. 2. Inter-visualization communication: Visualizations may communicate without prior knowledge of