Performance Evaluation of NPA-VM Using Attack Graph Hierarchical Visualization Approach

Internet attacks are on the rise and pose serious security threats to enterprise networks, commercial websites and to the millions of home internet users. Internet attacks are becoming more potent and complex with time. Network traffic visualization tools have successfully enabled security analysts to understand the nature of traffic present in a network. Conversely, these tools rely mainly on human expertise to discover anomalies in traffic and attack patterns. Human capacity to comprehend massive amounts of time-varying data is limited and network visualization tools need further visual aid to extract interesting patters from such large and complex data sets. Our approach is to search and highlight user-specified graph patterns in network traffic logs[1]. By visualizing a set of simple graph patterns, analysts can put together visual pieces of information conveyed by these smaller patterns and can learn about larger and more complex patterns. Theatrical performance of network traffic pattern in graphic language is visually intuitive, powerful and flexible specification and overcomes the limitation of poor pattern specification formats existing in the current tools. Therefore, our approach gives way to an iterative visual investigation and enables rapid discovery of more sophisticated attack patterns and anomalous features which are otherwise undetectable by standard network traffic visualization tools. [2]


NPA-VM (Network Pattern Analysis Based Vulnerability Measurement), Forecasting, Transformation, forecasting.