针对入侵检测系统警报日志传统的分析方法在处理海量信息时存在认知困难、实时交互性不强等问题,提出了基于入侵场景的可视化呈现系统,完成从警报日志到入侵场景的可视化过程,并利用3D游戏引擎将网络攻击过程在3D场景中展现出来.目标是使网络分析人员能够在更高层次对网络安全状况有深入的认识,以做出相应判断和应对.通过用户评价和性能测试实验证明其具备可用性并具有较强的可视化能力.
Traditional analyzing methods upon alert logs in intrusion detection system have the problems such as too heavy cognitive burden under massive information management and poor real-time and interactive ability. A visualization representation system based on intrusion scenarios is presented in this paper to realize visualization from alert log to attack scene and show the process of network attack at 3D scene with the utilization of 3D game engine. The goal is to give network analysts in-depth cognition for network security status at higher level to let them make proper decision-making and response. With user evaluation and performance test our system is proved to have both usability and strong visualization capability.