[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-seo-141716-105":3,"detail-sidebar-cat-0-en-105":81,"doc-detail-141716-en":130},{"code":4,"msg":5,"data":6},0,"ok",{"site_id":7,"language":8,"slug":9,"title":10,"keywords":11,"description":12,"schema_data":13,"social_meta":74,"head_meta":76,"extra_data":78,"updated_unix":80},105,"en","raven-real-time-attack-visualization-through-examining-network-flows-abstract","RAVEN - Real-time Attack Visualization through Examining Network flows - Abstract","","RAVEN is a real-time attack management project that fuses intrusion detection with network traffic data using network modeling and attack graph generation. The system visualizes network structure, traffic patterns, and compound exposures, highlighting latent relationships and prevailing attack vectors. It integrates three components: attack graph generation from XML network models and vulnerability data, Stream Aware Network Detection for protocol and endpoint identification, and DVNE for storing live stream data and rendering interactive graphical representations for operator decision-making.",{"@graph":14,"@context":73},[15,34,56],{"@type":16,"itemListElement":17},"BreadcrumbList",[18,23,27,31],{"item":19,"name":20,"@type":21,"position":22},"https://docshare.wps.com","Home","ListItem",1,{"item":24,"name":25,"@type":21,"position":26},"https://docshare.wps.com/document/","Document",2,{"item":28,"name":29,"@type":21,"position":30},"https://docshare.wps.com/document/research-report/","Research & Report",3,{"item":32,"name":10,"@type":21,"position":33},"https://docshare.wps.com/document/raven-real-time-attack-visualization-through-examining-network-flows-abstract/141716/",4,{"url":32,"name":10,"@type":35,"image":36,"author":41,"headline":10,"publisher":44,"fileFormat":47,"inLanguage":8,"description":12,"dateModified":48,"datePublished":49,"encodingFormat":47,"isAccessibleForFree":50,"interactionStatistic":51},"DigitalDocument",{"url":37,"@type":38,"width":39,"height":40},"https://docshare.wps.com/thumbnails/raven-real-time-attack-visualization-through-examining-network-flows-abstract/141716.png","ImageObject",300,407,{"name":42,"@type":43},"Terk","Person",{"url":19,"name":45,"@type":46},"DocShare","Organization","application/pdf","2026-09-19","2026-08-25",true,{"@type":52,"interactionType":53,"userInteractionCount":55},"InteractionCounter",{"@type":54},"ViewAction",9,{"@type":57,"mainEntity":58},"FAQPage",[59,65,69],{"name":60,"@type":61,"acceptedAnswer":62},"What problem does RAVEN target in real-time network attack management?","Question",{"text":63,"@type":64},"RAVEN targets the difficulty of acquiring relevant network intelligence, combining it with other security information, and presenting it in an intuitive way that supports sound decisions under real-time constraints.","Answer",{"name":66,"@type":61,"acceptedAnswer":67},"How does RAVEN generate an attack graph?",{"text":68,"@type":64},"RAVEN generates an exhaustive attack graph using a custom XML network model combined with vulnerability information exported in XML. It performs exhaustive searches over vulnerability combinations and logs unique vulnerability paths into an attack graph database.",{"name":70,"@type":61,"acceptedAnswer":71},"What roles do SAND and DVNE play in the system?",{"text":72,"@type":64},"SAND performs stream-aware network packet analysis to identify active protocols and source/destination IPs, maintaining streams until they time out. DVNE provides interactive multi-touch visualization that renders the network graph, layers live traffic data, and enables users to explore node details and highlight critical attack paths.","https://schema.org",{"og:url":32,"og:type":75,"og:title":10,"og:site_name":45,"og:description":12},"article",{"robots":77,"canonical":32},"index,follow",{"doc_id":79,"site_id":7},141716,1787663401,{"code":4,"msg":82,"data":83},"success",[84,88,92,96,101,106,111,115,119,122,126],{"id":22,"doc_module":4,"doc_module_name":25,"category_name":85,"show_sort_weight":86,"slug":87},"Story & Novel",90,"story-novel",{"id":26,"doc_module":4,"doc_module_name":25,"category_name":89,"show_sort_weight":90,"slug":91},"Literature",80,"literature",{"id":33,"doc_module":4,"doc_module_name":25,"category_name":93,"show_sort_weight":94,"slug":95},"Exam",70,"exam",{"id":97,"doc_module":4,"doc_module_name":25,"category_name":98,"show_sort_weight":99,"slug":100},5,"Comic",60,"comic",{"id":102,"doc_module":4,"doc_module_name":25,"category_name":103,"show_sort_weight":104,"slug":105},6,"Technology",50,"technology",{"id":107,"doc_module":4,"doc_module_name":25,"category_name":108,"show_sort_weight":109,"slug":110},7,"Healthcare",40,"healthcare",{"id":112,"doc_module":4,"doc_module_name":25,"category_name":29,"show_sort_weight":113,"slug":114},8,30,"research-report",{"id":55,"doc_module":4,"doc_module_name":25,"category_name":116,"show_sort_weight":117,"slug":118},"Religion & Spirituality",20,"religion-spirituality",{"id":117,"doc_module":4,"doc_module_name":25,"category_name":120,"show_sort_weight":117,"slug":121},"World Cup","world-cup",{"id":123,"doc_module":4,"doc_module_name":25,"category_name":124,"show_sort_weight":123,"slug":125},10,"Lifestyle","lifestyle",{"id":127,"doc_module":4,"doc_module_name":25,"category_name":128,"show_sort_weight":97,"slug":129},19,"General","general",{"code":4,"msg":82,"data":131},{"doc_id":79,"user_id":132,"nickname":42,"user_avatar":133,"doc_module":4,"category_id":112,"category_name":29,"doc_title":10,"doc_description":12,"doc_content":134,"file_id":135,"file_url":136,"file_type":137,"file_size":138,"view_count":55,"is_deleted":4,"is_public":22,"is_downloadable":22,"audit_status":22,"page_count":26,"language":139,"language_code":8,"site_id":7,"html_lang":8,"table_of_contents":140,"faqs":141,"seo_title":142,"seo_description":12,"update_tm":80,"read_time":97},1099525198933,"https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d","RAVEN: Real-time Attack Visualization through Examining Network flows  \nEthan Singleton, Matthew Young, Zach Harbort, George Louthan, Chris Hartney, Cody Pollet, John Hale University of Tulsa  \nABSTRACT  \nThis poster will describe the RAVEN project at the University of Tulsa’s Institute for Information Security (iSec) . RAVEN is being developed to fuse intrusion detection and network traffic data with network modeling and attack graph generation in a common framework that supports intuitive user interaction analysis. RAVEN visualizes networks, traffic patterns and compound exposures, displaying latent relationships and prevailing attack vectors. The poster will present the core technology elements of RAVEN and describe how they are integrated to yield a practical real time attack management solution.  \n1 Introduction  \nIdentifying, analyzing and responding to network attacks in real time are exercises fraught with several challenges. Acquiring the relevant network intelligence, integrating it meaningfully with other securityrelated information, and presenting the synthesized knowledge in an intuitive format conducive to sound decision-making present difficulties on their own. Combined under the constraints of real time attacks, the standard solution sets fail. RAVEN is a hybrid technology under development designed to overcome these challenges, allowing operators to rapidly identify, evaluate and mitigate on-going attacks.  \nRAVEN comprises three components: Attack Graph Generation, which takes in a network model and a list of vulnerabilities to generate an attack graph ; Stream Aware Network Detection (SAND), a tool for analyzing network packet information and the identification of network protocols; and Dynamic Visualization of Network Environments (DVNE), a tool that stores information gathered from SAND and produces a graphical representation of the network traffic.  \n2 Attack Graph Generation  \nRAVEN generates an exhaustive attack graph using a custom network model in an XML format. The model contains system information about each host on the network, and can be cross-referenced to vulnerability information from a source database. This information includes the operating system, software and services that are installed on the host, the IP address of machines that the host is directly connected to, and the open ports on the host. RAVEN is designed to utilize any vulnerability database that can be exported in XML format.  \nAn exhaustive search is performed to identify each possible vulnerability combination. The search algorithm allows RAVEN to use any host on the network as the root or goal node during attack graph generation. Each time a unique vulnerability path is detected, the path is logged in the attack graph database. The result of the search process is a comprehensive attack graph describing every possible combination of known attack over a network. This information is intelligently projected to the operator based on observations made from network traffic flow analysis.  \n3 SAND  \nActive network traffic flow analysis is a key enabler in RAVEN’s real time attack management scheme. SAND actively scans a network to identify incoming and outgoing protocols in each network stream, as  \nwell as for identifying source and destination IP addresses. Each time a new stream is detected, this information is passed to a logging module and added to the stream database. The same network stream is kept in the database until the stream times out. A timeout occurs when either the stream changes, such asthe protocol changing between source and destination IP, or when no packets are transmitted between the source and destination IP for a specified period of time.  \nRAVEN uses information gleaned from network traffic to cull the analytic space of the exhaustive attack graph. This aids both computational and cognitive scalability. Restricting the full attack graph to the elements participating in active traffic flows makes compound expos","cbCaii0nvqBseJuE","https://ap.wps.com/l/cbCaii0nvqBseJuE","pdf",91892,"English","# Introduction\n## Challenges in real-time network attack management\n## RAVEN overview and goals\n# Attack Graph Generation\n## XML network model and vulnerability database\n## Exhaustive search and attack graph projection\n# SAND\n## Stream-aware scanning of protocols and endpoints\n## Stream timeouts and analytic space reduction\n# DVNE\n## Multi-touch interactive visualization\n## Network graph rendering and secondary attack paths\n# RAVEN Architecture\n## Modular components and database tables\n## GUI integration and pruning/display","[{\"question\":\"What problem does RAVEN target in real-time network attack management?\",\"answer\":\"RAVEN targets the difficulty of acquiring relevant network intelligence, combining it with other security information, and presenting it in an intuitive way that supports sound decisions under real-time constraints.\"},{\"question\":\"How does RAVEN generate an attack graph?\",\"answer\":\"RAVEN generates an exhaustive attack graph using a custom XML network model combined with vulnerability information exported in XML. It performs exhaustive searches over vulnerability combinations and logs unique vulnerability paths into an attack graph database.\"},{\"question\":\"What roles do SAND and DVNE play in the system?\",\"answer\":\"SAND performs stream-aware network packet analysis to identify active protocols and source/destination IPs, maintaining streams until they time out. DVNE provides interactive multi-touch visualization that renders the network graph, layers live traffic data, and enables users to explore node details and highlight critical attack paths.\"}]","RAVEN - Real-time Attack Visualization through Examining Network flows - Abstract | PDF"]