A virtual machine platform and methodology for network data analysis with IDS and security visualization
David Freet, Rajeev K. Agrawal · 2017
Intrusion Detection Systems (IDS) provide a core defense technology for today's networks. However, as threats continue to increase in size and complexity, the amount of raw data generated by IDSs can quickly overwhelm security analysts who are tasked with sorting through the data in order to identify malicious traffic patterns. By combining security data visualization with IDS alerting and logging functionality, a more enhanced and efficient means of detecting network threats can be achieved. This analysis framework provides a Linux-based NetViz platform with select visualization tools, along with a user-friendly methodology for utilizing these tools in conjunction with IDS output to achieve greater threat detection efficiencies.