Panagiotis D. Ritsos

MEng PhD Essex, FHEA

Senior Lecturer in Visualization

XReality, Visualization and
Analytics (XRVA) Lab

Visualization, Data, Modelling and
Graphics (VDMG) research group,

School of Computer Science
and Engineering,

Bangor University,
Dean Street, Bangor,
Gwynedd, UK, LL57 1UT

Paper at IEEE VizSec 2015

Our publication Contextual Network Navigation; Situational Awareness for Network Administrators was presented in the IEEE Symposium on Visualization for Cyber Security held in conjunction with IEEE VIS2015. You can have a look at the accepted papers, news and updates from the symposium at VisSec.

Contextual Navigation Projection for AS34623 with AS5577 highlighted as a ‘network of interest’. The yellow nodes shown where AS5577 appears, allowing the user to visually reason potential blocking points.
Figure 1: Contextual Navigation Projection for AS34623 with AS5577 highlighted as a ‘network of interest’. The yellow nodes shown where AS5577 appears, allowing the user to visually reason potential blocking points. [PNG]

Abstract - One of the goals of network administrators is to identify and block sources of attacks from a network steam. Various tools have been developed to help the administrator identify the IP or subnet to be blocked, however these tend to be non-visual. Having a good perception of the wider network can aid the administrator identify their origin, but while network maps of the Internet can be useful for such endeavors, they are difficult to construct, comprehend and even utilize in an attack, and are often referred to as being “hairballs”. We present a visualization technique that displays pathways back to the attacker; we include all potential routing paths with a best-efforts identification of the commercial relationships involved. These two techniques can potentially highlight common pathways and/or networks to allow faster, more complete resolution to the incident, as well as fragile or incomplete routing pathways to/from a network. They can help administrators re-profile their choice of IP transit suppliers to better serve a target audience.

Reference

  • C. C. Gray, P. D. Ritsos, and J. C. Roberts, “Contextual Network Navigation; Situational Awareness for Network Administrators,” in IEEE Symposium on Visualization for Cyber Security (VizSec), Chicago, IL, USA, 2015.