Abstract
This article shows that malicious traffic flows such as denial-of-service attacks and various scanning activities can be visualized in an intuitive manner. A simple but novel idea of plotting a packet using its source IP address, destination IP address, and the destination port in a 3-dimensional space graphically reveals ongoing attacks. Leveraging this property, combined with the fact that only three header fields per each packet need to be examined, a fast attack detection and classification algorithm can be devised.
| Original language | English |
|---|---|
| Pages (from-to) | 30-39 |
| Number of pages | 10 |
| Journal | IEEE Network |
| Volume | 18 |
| Issue number | 5 |
| DOIs | |
| State | Published - Sep 2004 |