NetFlowMatrix: a visual approach for analysing large NetFlow data
Yingjie Chen, Baijian Yang, Weijie Wang
Abstract
Yingjie Chen, Baijian Yang, Weijie Wang
Abstract
NetFlowMatrix is a visual analytics system design that adopts small multiple charts to help analysts monitor NetFlow data of a computer network. This design provides an overview and drill-down interactions that allow analysts to see and analyse traffic data from a computer network of thousands of computers and millions of flow records. Various network activities generate NetFlow records with different characteristics. We grouped network flow information into a matrix of cells to display aggregate flows based on payload size and flow duration. The aggregate overview method is scalable that allows the design to support much larger computer networks. To visually distinguish extreme low and high quantity of flows, we use colour shades to distinguish different scales of cells. Utilising this innovative overview design, professionals can easily identify patterns and instances, obvious or subtle, from a large number of network flows.
OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
NetFlowMatrix is a visual analytics system design that adopts small multiple charts to help analysts monitor NetFlow data of a computer network. This design provides an overview and drill-down interactions that allow analysts to see and analyse traffic data from a computer network of thousands of computers and millions of flow records. Various network activities generate NetFlow records with different characteristics. We grouped network flow information into a matrix of cells to display aggregate flows based on payload size and flow duration. The aggregate overview method is scalable that allows the design to support much larger computer networks. To visually distinguish extreme low and high quantity of flows, we use colour shades to distinguish different scales of cells. Utilising this innovative overview design, professionals can easily identify patterns and instances, obvious or subtle, from a large number of network flows.
Key concepts: NetFlow, Computer science, Scalability, Aggregate (composite), Data mining, Payload (computing), Flow network, Database