|
ABSTRACT
This paper describes how a first person shooter (FPS) game engine can be leveraged for monitoring and control of enterprise IP data networks. Network administration can then occur in the following manner: network events (such as port scans or packets hitting a darknet) are translated in real time to various changes in the 3D game world state. Network administrators, logged in as 'players', can then collaboratively detect anomalous network events using the visual and aural cues given by the game. Using the native interaction metaphors from within the game (such as shooting, using or healing) they can then instantiate network administration policy changes (such as network layer firewall rules) directly back onto the running network without the need for interactions with complicated command line interfaces. We explore the possibilities offered by modern 3D game engines to implement this scheme as a server-side 'mod'. Finally, we detail the modifications made to the open source game engine 'Cube' to allow both the visualisation of large amounts of live network data within a virtual environment and support interacting with this data to create network administration events.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Brutal file manager. http://www.forchheimer.se/bfm/, August 2006.
|
| |
2
|
Cube (game/3d engine). http://cube.sourceforge.net/, August 2006.
|
| |
3
|
Enemy territory. http://games.activision.com/games/wolfenstein/, August 2006.
|
| |
4
|
The expect home page. http://expect.nist.gov/, August 2006.
|
| |
5
|
The freebsd project. http://www.freebsd.org/, August 2006.
|
| |
6
|
Honeyd honeypot project. http://www.honeyd.org/, August 2006.
|
| |
7
|
Hp openview management software. http://www.managementsoftware.hp.com/, August 2006.
|
| |
8
|
id software, doom 1, 2, quake 1, 2 and 3. http://www.idsoftware.com/, August 2006.
|
| |
9
|
Java 3d api. http://java.sun.com/products/java-media/3D/, August 2006.
|
| |
10
|
Mrtg: The multi router traffic grapher. http://people.ee.ethz.ch/oetiker/webtools/mrtg/, August 2006.
|
| |
11
|
Nagios. http://www.nagios.org/, August 2006.
|
| |
12
|
Netflow v9 export format. http://www.cisco.com/en/US/products/ps6601/products_white_paper09186a00801341b2.shtml, August 2006.
|
| |
13
|
Nmap security scanner for network exploration & hacking. http://www.insecure.org/nmap/, August 2006.
|
| |
14
|
opengl. http://www.opengl.org/, August 2006.
|
| |
15
|
Openssh. http://www.openssh.org/, August 2006.
|
| |
16
|
Rrdtool. http://people.ee.ethz.ch/oetiker/webtools/rrdtool/, August 2006.
|
| |
17
|
Serious games initiative. http://seriousgames.org/, August 2006.
|
| |
18
|
The team cymru darknet project. http://www.cymru.com/Darknet/, August 2006.
|
| |
19
|
Valve software. http://half-life2.com/, August 2006.
|
| |
20
|
Visualizing internet topology at a macroscopic scale. http://www.caida.org/analysis/topology/as_core_network/, August 2006.
|
| |
21
|
P. Abel, P. Gros, C. Santos, D. Loisel, and Paris. Automatic construction of dynamic 3d metaphoric worlds: An application to network management. In Visual Data Exploration and Analysis VII, volume 3960, pages 312--323, Jan 2002.
|
| |
22
|
M. Bailey, E. Cooke, T. Battles, and D. McPherson. Tracking global threats with the internet motion sensor. Technical report, October 2004.
|
| |
23
|
M. Bailey, E. Cooke, F. Jahanian, N. Provos, K. Rosaen, and D. Watson. Data reduction for the scalable automated analysis of distributed darknet traffic. In USENIX Internet Measurement Conference, pages 239--252, 2005.
|
| |
24
|
P. Biddle, P. England, M. Peinado, and B. Willman. The darknet and the future of content distribution. In In Proceedings of the 2002 ACM Workshop on Digital Rights Management. ACM Press, 2002.
|
| |
25
|
|
 |
26
|
|
| |
27
|
B. Cheswick, H. Burch, and S. Branigan. Mapping and visualizing the internet. In USENIX Annual Technical Conference, General Track, pages 1--12, 2000.
|
| |
28
|
B. Claise. Ipfix protocol specification, June 2006.
|
 |
29
|
|
 |
30
|
|
| |
31
|
W. Harrop and G. Armitage. Intuitive real-time network monitoring using visually orthogonal 3d metaphors. In Australian Telecommunications Networks & Applications Conference 2004 (ATNAC2004), December 2004.
|
| |
32
|
|
 |
33
|
|
 |
34
|
Blazej Kot , Burkhard Wuensche , John Grundy , John Hosking, Information visualisation utilising 3D computer game engines case study: a source code comprehension tool, Proceedings of the 6th ACM SIGCHI New Zealand chapter's international conference on Computer-human interaction: making CHI natural, p.53-60, July 07-08, 2005, Auckland, New Zealand
[doi> 10.1145/1073943.1073954]
|
 |
35
|
|
 |
36
|
|
| |
37
|
D. Moore, C. Shannon, G. M. Voelkery, and S. Savagey. Network telescopes. CAIDA Technical report, April 2004.
|
 |
38
|
|
 |
39
|
|
CITED BY
|
|
Leonardo M. Trejos , Masaru Kamada , Tatsuhiro Yonekura , Mamun Bin Ibne Reaz, Wildlife net-gamekeepers using sensor network, Proceedings of the 6th ACM SIGCOMM workshop on Network and system support for games, p.67-69, September 19-20, 2007, Melbourne, Australia
|
INDEX TERMS
Primary Classification:
K.
Computing Milieux
K.8
PERSONAL COMPUTING
K.8.0
General
Subjects:
Games
Additional Classification:
C.
Computer Systems Organization
C.2
COMPUTER-COMMUNICATION NETWORKS
C.2.3
Network Operations
General Terms:
Human Factors,
Management,
Measurement,
Performance,
Security
Keywords:
3D,
NIDS,
game modification,
greynet,
intrusion detection,
network control,
network monitoring,
real-time,
visualization
|