Downloads

PROPOSAL SEMINAR1 SEMINAR2 WRITEUP

Abstract

A network flow is a record that represents the characteristics associated with a unidirectional stream of packets between two hosts using an IP layer protocol. As a network flow only represents statistics relating to the data transferred in the stream, the effectiveness of utilising network flows for traffic visualisation to aid in cyber defence is not immediately apparent and needs further exploration. The goal of this research is to explore the use of network flows for data visualisation and geolocation.

A prototype system capable of collecting network flows exported using the NetFlow version 9 protocol designed and was implemented as part of this research to aid in this exploration. This system processes the collected flow records and renders the geolocated results on an interactive map in a web browser.

Using conformance testing it is shown that the prototype system is capable of collecting network flows and generating geolocated flow events in 50 milliseconds on the test platform. The system also provides functionality for the generation of heatmaps and tools for replaying flow events from the client browser for further visual analysis. A reporter tool has also been developed to produce monthly reports on the collected network flows.