visualization tool for network forensics analysis using an intrusion detection system ( cyber viz )

10
Visualization tool for network forensics analysis using an Intrusion Detection System ( Cyber ViZ )

Upload: arron-howard

Post on 26-Dec-2015

221 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Visualization tool for network forensics analysis using an Intrusion Detection System ( Cyber ViZ )

Visualization tool for network forensics analysis using an Intrusion Detection System

( Cyber ViZ )

Page 2: Visualization tool for network forensics analysis using an Intrusion Detection System ( Cyber ViZ )

Project ID: - PIT-58

Project Team:-

Project Coordinator :- Mr. Jayantha Amaraarachchi Project Supervisor : - Mr. Lakmal Rupasinghe 

DIT Number Name

DIT/06/E1/2022 Abeyrathne K.B.

DIT/06/E1/2028 Yaparathna Y.M.P.K.B.

DIT/06/E1/2025 Ilangarathna I.M.

DIT/06/E1/2008 Wadigamangawa A.H.M.S.D.B.

DIT/06/E1/2017 De Silva D.P.H.R.

Our Team Members …

CyberViZ 2

Page 3: Visualization tool for network forensics analysis using an Intrusion Detection System ( Cyber ViZ )

Introduction …

3CyberViZ

What is network forensic?

Network Forensics is used to find evidence of such Attacks

Recognize Threats through the IDS

Benefits of Visualize Network Traffic

Provide better way to collect evidence

Page 4: Visualization tool for network forensics analysis using an Intrusion Detection System ( Cyber ViZ )

Existing Systems and Research

4CyberViZ

Existing Systems

Ethereal TNV VisFlowConnect-IP

Page 5: Visualization tool for network forensics analysis using an Intrusion Detection System ( Cyber ViZ )

Features of our system

5CyberViZ

Intrusion Detection System

Packet capturing & Extracting methods

Network traffic visualization

Page 6: Visualization tool for network forensics analysis using an Intrusion Detection System ( Cyber ViZ )

Our System

6CyberViZ

Page 7: Visualization tool for network forensics analysis using an Intrusion Detection System ( Cyber ViZ )

7

System Overview

CyberViZPIT-58

Page 8: Visualization tool for network forensics analysis using an Intrusion Detection System ( Cyber ViZ )

Benefits

8CyberViZ

Simplify network forensic analysis through less complex visuals.

Integrating an IDS with a network visualization tool for network forensic analysis to be more convenient

Detecting network attacks through the forensic analysis which cannot be detected by a normal IDS

Platform independence

PIT-58

Page 9: Visualization tool for network forensics analysis using an Intrusion Detection System ( Cyber ViZ )

9

Technology Requirements

CyberViZPIT-58

Need a switched network with “snort” IDS in every host in network.

Need centralized MySQL database.(Using Wamp Server)• Jpcap – Windows/Linux• Libpacp – Linux• Winpcap – Windows• Snort – Windows/Linux

Page 10: Visualization tool for network forensics analysis using an Intrusion Detection System ( Cyber ViZ )

ThankThank You You ……