CUBE-ism: An Interactive Visual Analytics System for Real-Time Darknet Traffic Triage

Authors

Kanta Okugawa (NICT), Koei Suzuki (NICT), Masaki Kubo (NICT), Ryutaro Ushigome (NICT), Yukiko Endo (NICT), Takahiro Kasama (NICT)

Presentation

Session
Let's figure out how things work behind the scenes
Time
Wednesday, Nov 11, 14:00 – 14:12 (US/Eastern) · session 13:00 – 14:30
Location
Hall America north

Keywords

Visual analytics for cybersecurity, darknet monitoring, real-time visualization

Abstract

The Internet has become indispensable to modern society, but its growing scale and ubiquity have been accompanied by a steady increase in cyberattacks, ranging from financially motivated crimes to state-sponsored operations. Responding effectively to such threats requires timely identification and triage of emerging malicious activity. Darknet monitoring provides a valuable means of observing indiscriminate cyberattacks by capturing traffic directed to unused yet reachable global IP address space. Such traffic includes malware scanning, probing by security organizations, DDoS backscatter, and misconfiguration traffic. In operational settings, analysts must examine large volumes of heterogeneous darknet traffic by combining multiple attributes, including port numbers, packet timing, header features, and geographic information, in order to identify attack patterns, suspicious hosts, and high-priority events for triage. In this paper, we present CUBE-ism, an interactive visual analytics system for real-time analysis of darknet traffic. CUBE-ism represents packet sources and destinations on opposing faces of a cube, maps IP addresses and port numbers to its axes, and visualizes packets as transitions between them. It integrates attribute enrichment, interactive filtering, and statistical summaries within a unified interface, allowing analysts to iteratively refine exploration conditions and rapidly identify distinctive behaviors. To support real-time analysis at scale, we also design a data processing pipeline that enables flexible filtering and statistical aggregation over large volumes of traffic. Through real-world operational use cases, we show that CUBE-ism helps analysts identify distinctive traffic patterns and supports practical cyberattack triage.

For Practitioners

This paper may be of interest to network security analysts, network operators, and researchers analyzing large-scale Internet traffic. Practitioners can apply the proposed visual analytics approach to identify traffic patterns, test hypotheses through interactive filtering, and prioritize events for further investigation and monitoring.