A lot of companies (partners) are using the Internet-Analysis-System. This system is useful to analyse the local network (local view / local situation). Once implemented, evaluation of the local situation will be easier by having a reference view, which shows the whole situation (global view) of all partners. In other areas this is a standard procedure. A global view of the internet enables us to evaluate the local view. There aren’t many institutions or corporations, which have the option to realize a global view. The if(is) is able to serve a global view.
The local views of our partners are combined (anonymous). The combined visualization creates a global view. A virtual probe represents the global view which transmits it to all partners (see figure1). The principles of privacy and confidentiality aren’t harmed by generating the global view. The partners can’t be identified when analysing the global view.
Also the global view is useful to optimize Early Warning Systems. Global anomalies and attacks can be monitored. The alert module of the Internet Analysis System will warn the responsible admin, who in turn is then able to initiate retaliatory actions. Further statistic measures like the charting of trends or the comparison of individual protocols to create profiles, are also available by using the global view. The profiles are useful to optimize the anomaly detection.
If(is) is currently researching to find an opportunity to generate a global view which knows no time-zone. An attack doesn’t cares in which time-zone the root an the goal is. So an attack only can be found in a time-zone independent context.
Contact
Institute for Internet-Security
Faculty: Computer Sciences
Dominique Petersen
Westfälische Hochschule, University of Applied Sciences
Neidenburger Str. 43
45877 Gelsenkirchen
E-Mail: petersen
internet-sicherheit.de
Phone: 0209 9596 766












