VisSRA: Visualizing snort rules and alerts

Xiaojin Hong*, Changzhen Hu, Zhigang Wang, Guoqiang Wang, Ying Wan

*此作品的通讯作者

科研成果: 会议稿件论文同行评审

5 引用 (Scopus)

摘要

Snort is a rule-based intrusion detection system, applying defined rules to inspect suspicious packets in network. An alert will be generated if an alert rule is triggered. Analysis of the relation between rules and alerts can help network administrators to analyze alerts easily so as to identify network attacks. The aim of this work is to develop a visualization tool that can be used to view the rules and alerts in visualization. The proposed visualization tool, which is called VisSRA, also can be used to find the relation between rules and alerts, view the number of alerts triggered by a rule and check the alerts quickly. Tree maps were used to visualize rules Snort contains and alerts Snort generates which are shown as cells with different colors. The system uses the graphical and statistical manners to allow even novices to get an overview of network state. In this paper, an experiment was given to show the proposed approach could bring some convenience of browsing and analyzing network anomalies to administrators.

源语言英语
441-444
页数4
DOI
出版状态已出版 - 2012
活动4th International Conference on Computational Intelligence and Communication Networks, CICN 2012 - Mathura, Uttar Pradesh, 印度
期限: 3 11月 20125 11月 2012

会议

会议4th International Conference on Computational Intelligence and Communication Networks, CICN 2012
国家/地区印度
Mathura, Uttar Pradesh
时期3/11/125/11/12

指纹

探究 'VisSRA: Visualizing snort rules and alerts' 的科研主题。它们共同构成独一无二的指纹。

引用此