Using relational graphs for exploratory analysis of network traffic data
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216224%3A14610%2F23%3A00130589" target="_blank" >RIV/00216224:14610/23:00130589 - isvavai.cz</a>
Result on the web
<a href="https://doi.org/10.1016/j.fsidi.2023.301563" target="_blank" >https://doi.org/10.1016/j.fsidi.2023.301563</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1016/j.fsidi.2023.301563" target="_blank" >10.1016/j.fsidi.2023.301563</a>
Alternative languages
Result language
angličtina
Original language name
Using relational graphs for exploratory analysis of network traffic data
Original language description
The human brain is designed to perceive the surrounding world as associations. These associations between the individual pieces of information allow us to analyze and categorize new inputs and thus understand them. However, the support for association-based analysis in traditional network analysis tools is only limited or not present at all. These tools are mostly based on manual browsing, filtering, and aggregation, with only basic support for statistical analyses and visualizations for communicating the general characteristics. Yet, it is the relationship diagram that could allow the analysts to get a broader context and reveal the associations hidden in the data. In this paper, we explore the possibilities of relational analysis as a novel paradigm for network forensics. We provide a set of user requirements based on the discussion with domain experts and introduce a novel visual analysis tool utilizing multimodal graphs for modeling relationships between entities from captured packet traces. Finally, we demonstrate the relational analysis process on two use cases and discuss feedback from domain experts.
Czech name
—
Czech description
—
Classification
Type
J<sub>imp</sub> - Article in a specialist periodical, which is included in the Web of Science database
CEP classification
—
OECD FORD branch
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Result continuities
Project
<a href="/en/project/EF16_019%2F0000822" target="_blank" >EF16_019/0000822: CyberSecurity, CyberCrime and Critical Information Infrastructures Center of Excellence</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Others
Publication year
2023
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Name of the periodical
Forensic Science International: Digital Investigation
ISSN
2666-2825
e-ISSN
2666-2817
Volume of the periodical
45
Issue of the periodical within the volume
S
Country of publishing house
US - UNITED STATES
Number of pages
10
Pages from-to
1-10
UT code for WoS article
001049948800008
EID of the result in the Scopus database
2-s2.0-85169837809