One area of interest that I have is network visualization. What I'm referring to is being able to visually see the traffic flows and patterns to determine anomolies or events of interest. We have so much information with our networks today, that it is difficult to process all of it. The trend seems to be getting worse and reverting back to my good ole Army days of Do more with less. With the economic times we live it, it always seems that security is one area that takes a hit. So, we have to work smarter and network visualization is one area that Ithink has great potential, but seems to be very under developed.
I haven't explored what's out there in a couple of years. What was out there that I experimented with it were tools such as:
Time-based Network Traffic Visualizer (TNV)
Spinning Cube of Potential Doom
However, these tools had a long ways to go before they could really be effective on a large scale. Some were java based and SLOW (others were just slow) when processing any significant amount of data. However, what they did do, was pretty impressive for being able to visually make sense of a pcap file or your netflow data. They work great for looking at small chunks of traffic and helping immediately see anomolies. If this could just be channeled into a near real-time scenario for monitoring networks, that would be fantastic.
I did some quick google searches and didn't turn up any thing new in this arena. If anyone has any experience with network visualization or knows of any tools or workbeing done, please let us know.
(c) SANS Internet Storm Center. http://isc.sans.org Creative Commons Attribution-Noncommercial 3.0 United States License.