Skip to main content

Existence Plots: A Low-Resolution Time Series for Port Behavior Analysis

  • Conference paper
Visualization for Computer Security (VizSec 2008)

Part of the book series: Lecture Notes in Computer Science ((LNSC,volume 5210))

Included in the following conference series:

Abstract

An existence plot is a low-resolution visualization that concurrently represents the activity of all 216 ports on a single host. By doing so, we are able to show patterns of port usage which can indicate server activity and demonstrate scanning. In this work we introduce the existence plot as a visualization and discuss its use in gaining insight into a host’s behavior.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. Collins, M., Shimeall, T., Faber, S., Janies, J., Weaver, R., De Shon, M., Kadane, J.: Using uncleanliness to predict future botnet addresses. In: Proceedings of IMC 2007 (2007)

    Google Scholar 

  2. Hernandez-Campos, F., Nobel, A., Smith, F., Jeffay, K.: Understanding patterns of tcp connection usage with statistical clustering. In: Proceedings of MASCOTS 2005. IEEE Computer Society, Los Alamitos (2005)

    Google Scholar 

  3. Lakkaraju, K., Yurcik, W., Lee, A.: Nvisionip: netflow visualizations of system state for security situational awareness. In: Proceedings of VizSEC 2004 (2004)

    Google Scholar 

  4. Mansmann, F., Meier, L., Keim, D.: Visualization of host behavior for network security. In: Proceedings of VizSEC 2007 (2007)

    Google Scholar 

  5. Marchette, D.: Computer Intrusion Detection and Network Monitoring: A Statistical Viewpoint. Springer, New York (2001)

    MATH  Google Scholar 

  6. McPherson, J., Ma, K., Krystosek, P., Bartoletti, T., Christensen, M.: Portvis: a tool for port-based detection of security events. In: Proceedings of VizSEC/DMSEC 2004. ACM, New York (2004)

    Google Scholar 

  7. Pang, R., Yegneswaran, V., Barford, P., Paxson, V., Peterson, L.: Characteristics of internet background radiation. In: Proceedings of IMC 2004 (2004)

    Google Scholar 

  8. Wright, C., Monrose, F., Masson, G.: Using visual motifs to classify encrypted traffic. In: proceedings of VizSEC 2006. ACM Press, New York (2006)

    Google Scholar 

  9. Xiao, L., Gerth, J., Hanrahan, P.: Enhancing visual analysis of network traffic using a knowledge representation. VAST 0, 107–114 (2006)

    Google Scholar 

  10. Yegneswaran, V., Barford, P., Ullrich, J.: Internet intrusions: Global characteristics and prevalence. In: Proceedings of ACM SIGMETRICS 2003 (2003)

    Google Scholar 

  11. Yin, X., Yurcik, W., Treaster, M., Li, Y., Lakkaraju, K.: Visflowconnect: netflow visualizations of link relationships for security situational awareness. In: Proceedings of VizSEC/DMSEC 2004. ACM Press, New York (2004)

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Editor information

John R. Goodall Gregory Conti Kwan-Liu Ma

Rights and permissions

Reprints and permissions

Copyright information

© 2008 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Janies, J. (2008). Existence Plots: A Low-Resolution Time Series for Port Behavior Analysis. In: Goodall, J.R., Conti, G., Ma, KL. (eds) Visualization for Computer Security. VizSec 2008. Lecture Notes in Computer Science, vol 5210. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-85933-8_16

Download citation

  • DOI: https://doi.org/10.1007/978-3-540-85933-8_16

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-540-85931-4

  • Online ISBN: 978-3-540-85933-8

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics