Sonification of network traffic flow for monitoring and situational awareness.

Maintaining situational awareness of what is happening within a computer network is challenging, not only because the behaviour happens within machines, but also because data traffic speeds and volumes are beyond human ability to process. Visualisation techniques are widely used to present informati...

Full description

Bibliographic Details
Main Authors: Mohamed Debashi, Paul Vickers
Format: Article
Language:English
Published: Public Library of Science (PLoS) 2018-01-01
Series:PLoS ONE
Online Access:http://europepmc.org/articles/PMC5908141?pdf=render
id doaj-8a6ad4c2cb4940de8eab03a52cd60a3c
record_format Article
spelling doaj-8a6ad4c2cb4940de8eab03a52cd60a3c2020-11-24T21:09:55ZengPublic Library of Science (PLoS)PLoS ONE1932-62032018-01-01134e019594810.1371/journal.pone.0195948Sonification of network traffic flow for monitoring and situational awareness.Mohamed DebashiPaul VickersMaintaining situational awareness of what is happening within a computer network is challenging, not only because the behaviour happens within machines, but also because data traffic speeds and volumes are beyond human ability to process. Visualisation techniques are widely used to present information about network traffic dynamics. Although they provide operators with an overall view and specific information about particular traffic or attacks on the network, they often still fail to represent the events in an understandable way. Also, because they require visual attention they are not well suited to continuous monitoring scenarios in which network administrators must carry out other tasks. Here we present SoNSTAR (Sonification of Networks for SiTuational AwaReness), a real-time sonification system for monitoring computer networks to support network administrators' situational awareness. SoNSTAR provides an auditory representation of all the TCP/IP traffic within a network based on the different traffic flows between between network hosts. A user study showed that SoNSTAR raises situational awareness levels by enabling operators to understand network behaviour and with the benefit of lower workload demands (as measured by the NASA TLX method) than visual techniques. SoNSTAR identifies network traffic features by inspecting the status flags of TCP/IP packet headers. Combinations of these features define particular traffic events which are mapped to recorded sounds to generate a soundscape that represents the real-time status of the network traffic environment. The sequence, timing, and loudness of the different sounds allow the network to be monitored and anomalous behaviour to be detected without the need to continuously watch a monitor screen.http://europepmc.org/articles/PMC5908141?pdf=render
collection DOAJ
language English
format Article
sources DOAJ
author Mohamed Debashi
Paul Vickers
spellingShingle Mohamed Debashi
Paul Vickers
Sonification of network traffic flow for monitoring and situational awareness.
PLoS ONE
author_facet Mohamed Debashi
Paul Vickers
author_sort Mohamed Debashi
title Sonification of network traffic flow for monitoring and situational awareness.
title_short Sonification of network traffic flow for monitoring and situational awareness.
title_full Sonification of network traffic flow for monitoring and situational awareness.
title_fullStr Sonification of network traffic flow for monitoring and situational awareness.
title_full_unstemmed Sonification of network traffic flow for monitoring and situational awareness.
title_sort sonification of network traffic flow for monitoring and situational awareness.
publisher Public Library of Science (PLoS)
series PLoS ONE
issn 1932-6203
publishDate 2018-01-01
description Maintaining situational awareness of what is happening within a computer network is challenging, not only because the behaviour happens within machines, but also because data traffic speeds and volumes are beyond human ability to process. Visualisation techniques are widely used to present information about network traffic dynamics. Although they provide operators with an overall view and specific information about particular traffic or attacks on the network, they often still fail to represent the events in an understandable way. Also, because they require visual attention they are not well suited to continuous monitoring scenarios in which network administrators must carry out other tasks. Here we present SoNSTAR (Sonification of Networks for SiTuational AwaReness), a real-time sonification system for monitoring computer networks to support network administrators' situational awareness. SoNSTAR provides an auditory representation of all the TCP/IP traffic within a network based on the different traffic flows between between network hosts. A user study showed that SoNSTAR raises situational awareness levels by enabling operators to understand network behaviour and with the benefit of lower workload demands (as measured by the NASA TLX method) than visual techniques. SoNSTAR identifies network traffic features by inspecting the status flags of TCP/IP packet headers. Combinations of these features define particular traffic events which are mapped to recorded sounds to generate a soundscape that represents the real-time status of the network traffic environment. The sequence, timing, and loudness of the different sounds allow the network to be monitored and anomalous behaviour to be detected without the need to continuously watch a monitor screen.
url http://europepmc.org/articles/PMC5908141?pdf=render
work_keys_str_mv AT mohameddebashi sonificationofnetworktrafficflowformonitoringandsituationalawareness
AT paulvickers sonificationofnetworktrafficflowformonitoringandsituationalawareness
_version_ 1716757021544415232