Version Tomorrow is the first day of the rest of your life
workshop: Network Traffic Analysis using Deep Packet Inspection and Data Visualization
Eventpad: the Sublime editor for network traffic

For the protection of (critical) infrastructures against complex virus attacks, deep packet inspection is unavoidable. In our project SpySpot we are developing new tools and techniques to assist analysts in gaining insight and reverse engineering WireShark PCAP files. In this talk we present and demo a new data visualization system Eventpad to study PCAP traffic by visualizing patterns according to user-defined rules. We illustrate the effectiveness of the system on real-world traffic including VoIP communication and Ransomware activity in file systems.
#NetworkSecurity #DeviceSecurity
The difference between expected and actual behavior in network traffic is nearly impossible to prevent. In order to discover and understand potential bottlenecks in network environments, we propose a visual analytics approach to the analysis of PCAP traffic. Discovery of computer viruses or suboptimal resource usage in the traffic for instance can assist analysts in debugging and optimizing their system. In this research we study how visualization of PCAP communication can help domain experts in understanding whether their system operates as desired.
Info
Day:
2017-08-06
Start time:
22:40
Duration:
00:30
Room:
Re
Track:
Curated by SHA2017
Links:
- iCalendar
- EventPad demo video (VoIP/SIP traffic)
- Information about SpySpot
- Other systems we designed (SNAPS, Office network)
- Other systems we designed (CoNTA, Industrial Control traffic)
Feedback
Click here to let us know how you liked this event.
Concurrent Events
Speakers
ArrayX |