Effective network management via dynamic network anomaly visualization
Qi Liao and
Ting Li
International Journal of Network Management, 2016, vol. 26, issue 6, 461-491
Abstract:
Managed network has become increasingly large, complex, heterogeneous, and dynamic. With tremendous number of network components changing at any moment, deciding which events and changes are possibly abnormal and need further investigation is extremely challenging. While there has been widely adopted practice to log daily activities through standard file formats such as netflow, syslog, firewall, and IDS systems, it is vital for system administrators and network managers to be able to analyze the vast amount of log data in order to detect suspicious behaviors or patterns, possibly because of malicious users/applications or faulty devices. While there are automated systems that are available to generate warnings, whether such alarms are true or false, and more importantly, what are the underlying causes are still difficult to know. To bridge the gap between network logging and anomaly analysis, we design and implement a visualization tool that combines multiple useful visualizations together with algorithms such as graph link anomaly analysis. We study the effects of different visualization methods on detecting and analyzing network and system anomalous events and their causes and show that these views, when combined and linked together, may provide an effective alternative for network management and anomaly analysis. Copyright © 2016 John Wiley & Sons, Ltd.
Date: 2016
References: View references in EconPapers View complete reference list from CitEc
Citations:
Downloads: (external link)
https://doi.org/10.1002/nem.1945
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:wly:intnem:v:26:y:2016:i:6:p:461-491
Access Statistics for this article
More articles in International Journal of Network Management from John Wiley & Sons
Bibliographic data for series maintained by Wiley Content Delivery ().