现代互联网络存在认知负担重、缺乏全局认知、交互性较差等安全问题。为此,利用可视化方法识别网络中的攻击和异常事件,并提出一种新型的入侵检测分析系统(IDs)——基于辐射状面板可视化技术的IDSView。根据现有可视化系统的不足,考虑用户接口与体验,采用颜色混合算法、多段拟合贝塞尔曲线算法、数据预处理及端口映射算法,降低图像的闭塞性,提高可扩展性及增强入侵识别与态势感知能力。应用结果表明,应用该方法分析人员可以直观地从宏观和微观2个层面感知网络安全状态,有效地识别网络攻击,辅助分析人员决策。
There are some security problem of cognition difficulty, lack of global cognition and interaction in modem Intemet security. How to identify network attacks and abnormal events in a quicker and more effective way is a key and eternal topic. The visualization method, a possible and valuable solution, is proposed. Considering the features and defeats of current working visualization systems, this paper researches and constructs a new type of Intrusion Detection System(IDS) IDS View, a system based on radial panel visualization technology. With a main focus on user interface and experience, decrease of image occlusion, color mixing algorithms, curve algorithms and port mapping algorithms, this system can well be applied to the campus network security situation assessment. Application results show that analysts can intuitively be aware of the network security status from both macro and micro levels, so it can effectively identify network attacks and assist them in decision-making.