Netinfo Security ›› 2016, Vol. 16 ›› Issue (2): 40-46.doi: 10.3969/j.issn.1671-1122.2016.02.007

• Orginal Article • Previous Articles     Next Articles

Research and Implement on Network Visual Analytic System Based on TcpFlow

Hao MENG1,2,3, Jinsong WANG1,2,3(), Jingyun HUANG1,2,3, Huirong NAN1,2,3   

  1. 1. School of Computer and Communication Engineering, Tianjin University of Technology, Tianjin 300384, China
    2. Tianjin Key Laboratory of Intelligence Computing and Novel Software Technology, Tianjin 300384, China
    3. National Engineering Laboratory for Computer Virus Prevention and Control Technology, Tianjin 300457,China
  • Received:2015-12-14 Online:2016-02-10 Published:2020-05-13

Abstract:

This paper designs a visual analytic system for analyzing the structure of network by using TcpFlow data. Its functions include distinguishing the hosts between clients and servers in the network, dividing the topology of network, classing the servers, and finding communication modes. The system has two modules. The first module is used to analyze the structure and hosts of the network by visual analysis of the TcpFlow data. And we can also use it to discover special communication modes through visualizing the session procedures of the TcpFlow data. Meanwhile, the second module can be used to analyze the network communication modules real-timely. With these two modules, the system can help network administrators and network security analysts understand the structure of the whole network and characteristics of the network quickly, and make it convenient to the management of the network and perception of network security situation.

Key words: analysis of network structure, network communication mode, TcpFlow, visual analysis

CLC Number: