Network-wide intrusion detection supported by multivariate analysis and interactive visualization

Referencia completa:

Therón Sánchez, R., Magán-Carrión, R., Camacho, J. & Maciá-Fernández, G. Network-wide intrusion detection supported by multivariate analysis and interactive visualization, Phoenix, AZ, USA, IEEE, VizSec 2017. 2017.

Ver video

Abstract:

In this paper, we introduce a new visualization tool for network-wide intrusion detection. It is based in multivariate anomaly detection with a combination between Principal Component Analysis (PCA) and a new variant called Group-wise PCA (GPCA). Combining these methodologies with the capabilities of interactive visualization, the resulting tool is a highly flexible and intuitive interface that allows the user to navigate through the enormous amount of data collected in the network, in order to find anomalous or unexpected behaviors. We use a real case study to illustrate the capability of the tool to unveil the complex mixture of information that can be found in network security/traffic data and identify and diagnose anomalies in it.

[Pulse aquí para ver el artículo completo]