Title
VAST 2012 Mini-Challenge 2: Chart- and Matrix-based approach to network operations forensics
Abstract
We report the approach and results on the VAST 2012 MiniChallenge 2: Bank of Money Regional Office Network Operations Forensics. Using commercial data mining, visualization and database software such as KNIME, Tableau and MySQL as well as a custom-written source vs. destination IP pixel matrix, our team of students identified suspicious IRC traffic, an attack on the firewall, a drop in the firewall connections, an attempt for sensitive information exchange and a possible Distributed Denial-of-Service attack executed partly from a host within the bank network.
Year
DOI
Venue
2012
10.1109/VAST.2012.6400513
Visual Analytics Science and Technology
Field
DocType
ISSN
Data mining,Firewall (construction),Network forensics,Matrix (mathematics),Computer security,Computer science,Visualization,Network operations center,Chart,Information sensitivity
Conference
2325-9442
ISBN
Citations 
PageRank 
978-1-4673-4752-5
1
0.38
References 
Authors
0
7
Name
Order
Citations
PageRank
jan hildenbrand130.77
danielionut paval210.38
prakash thapa311.06
christian rohrdantz410.38
Florian Mansmann558935.91
Enrico Bertini6115457.38
Tobias Schreck71854123.28