Security alert aggregation and visualisation
Wajahath Nazal, Aishwarya Shivani R · International journal of advanced research in computer science and electronics engineering · 2018
With the augmentation of attacks on computer networks, a need for monitoring the network traffic becomes obligatory. Network analyst recognizes the anomalies of network by analyzing alert messages and traffic data generated by these monitoring devices. The time taken to analyze and inspect overwhelming amount of security logs and events is exponential, that is where data aggregation comes into picture. On account of similarity of the security notification generated using K-means clustering-based algorithm, the data can be aggregated. An efficient technique for analyzing and examining network security could be executed through visualization. Furthermore, implementing network security visualization will significantly facilitate to detect, perceive and defend the network from being attacked by the anomalies. In this project, data visualization is achieved by the use of Matplotlib library. A colour coded bar graph obtained from Matplotlib will aid the network analysts in understanding and precisely tackle the events of network security. K-means aggregation technique is used in order to aggregate the data from a pre-determined data set which is then fed to software tool named Jupyter for visualization.