NetViewer:

A Network Traffic Visualization and Analysis Tool


The frequent and large-scale network attacks have led to an increased need for developing techniques for analyzing network traffic. If efficient analysis tools were available, it could become possible to detect the attacks, anomalies and to appropriately take action to contain the attacks before they have had time to propagate across the network. This paper describes NetViewer, a network monitoring tool that can simultaneously detect, identify and visualize attacks and anomalous traffic in real-time by passively monitoring packet headers. Treating the traffic data as the image, the door for applying image/video processing for the analysis of network traffic has been opened.

NetViewer is released free to the general public. By employing a freely available visualization tool, the users of NetViewer can comprehend the characteristics of the network traffic observed in the aggregate. NetViewer can be employed to detect and identify network anomalies such as DoS attacks, worms and flash crowds. NetViewer can also provide information on traffic distributions over IP address/port number domains, utilization of link capacity and effectiveness of Quality of Service policies.

NetViewer is supported by an NSF grant ANI-0087372, Texas Higher Education Board, Texas Information Technology and Telecommunications Taskforce and Intel Corp.


The Demonstration Screen

NetViewer v0.1 Demo ( AVI ) Please be patient for downloading!

Demo for Window indeo compressed format ( AVI ) After downloading, try to play it off-line


Project Members

A. L. Narasimha Reddy, principal investigator

Seong Soo Kim, former graduate student, now at Samsung

Graham Booker, graduate student


Source Code Release

netviewer.zip

If you have any questions in installing and running NetViewer, E-mail us at skim@ee.tamu.edu or kimseongsoo2@hotmail.com

 

Go to the Main