skip to main content
10.1145/1179576.1179587acmconferencesArticle/Chapter ViewAbstractPublication PagesccsConference Proceedingsconference-collections
Article

Tool update: high alarm count issues in IDS rainstorm

Published: 03 November 2006 Publication History

Abstract

We developed a tool to help network administrators deal with the large amount of alarms generated from network security appliances. It efficiently uses screen space representing a high number of IP addresses along with time sequence so that general alarm activity for a network can be visualized along with details, if desired. The tool was useful but encountered problems when there was a significant increase in the amount of alarms. The issues that resulted are addressed in this paper along with methods to ease them.

References

[1]
K. Abdullah, C. Lee, G. Conti, J. Copeland, and J. Stasko. Ids rainstorm: Visualizing ids alarms. In IEEE Symposium on Information Visualization's Workshop on Visualization for Computer Security (VizSEC), pages 1--10, 2005.
[2]
G. Conti, K. Abdullah, J. Grizzard, J. Stasko, J.A. Copeland, M. Ahamad, H.L. Owen, and C. Lee. Countering security information overload through alert and packet visualization. IEEE Computer Graphics and Applications, 2006.
[3]
G. Conti, M. Ahamad, and J. Stasko. Attacking information visualization system usability: Overloading and deceiving the human. In Symposium on Usable Privacy and Security (SOUPS), July 2005.

Cited By

View all
  • (2016)A Survey on Information Visualization for Network and Service ManagementIEEE Communications Surveys & Tutorials10.1109/COMST.2015.245053818:1(285-323)Online publication date: Sep-2017
  • (2010)Multistage attack detection system for network administrators using data miningProceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence Research10.1145/1852666.1852722(1-4)Online publication date: 21-Apr-2010
  • (2010)Alerts visualization and clustering in network-based intrusion detectionProceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence Research10.1145/1852666.1852712(1-4)Online publication date: 21-Apr-2010
  • Show More Cited By

Recommendations

Comments

Information & Contributors

Information

Published In

cover image ACM Conferences
VizSEC '06: Proceedings of the 3rd international workshop on Visualization for computer security
November 2006
138 pages
ISBN:1595935495
DOI:10.1145/1179576
Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

Sponsors

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 03 November 2006

Permissions

Request permissions for this article.

Check for updates

Author Tags

  1. IDS alarm visualization
  2. filtering network data
  3. network security information visualization

Qualifiers

  • Article

Conference

CCS06
Sponsor:

Upcoming Conference

CCS '25

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)1
  • Downloads (Last 6 weeks)0
Reflects downloads up to 01 Mar 2025

Other Metrics

Citations

Cited By

View all
  • (2016)A Survey on Information Visualization for Network and Service ManagementIEEE Communications Surveys & Tutorials10.1109/COMST.2015.245053818:1(285-323)Online publication date: Sep-2017
  • (2010)Multistage attack detection system for network administrators using data miningProceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence Research10.1145/1852666.1852722(1-4)Online publication date: 21-Apr-2010
  • (2010)Alerts visualization and clustering in network-based intrusion detectionProceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence Research10.1145/1852666.1852712(1-4)Online publication date: 21-Apr-2010
  • (2010)Alerts Analysis and Visualization in Network-based Intrusion Detection SystemsProceedings of the 2010 IEEE Second International Conference on Social Computing10.1109/SocialCom.2010.120(785-790)Online publication date: 20-Aug-2010

View Options

Login options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

Figures

Tables

Media

Share

Share

Share this Publication link

Share on social media