Search

Network traffic analysis

Graph Timeline Cyber Security

Use this showcase if you’re building an application where analysts need to investigate network activity from timestamped log data. It shows how traffic records can become a visual sequence, making unusual behavior easier to spot than it would be in raw log files.

What the showcase demonstrates

The showcase presents a network traffic log as a timeline alongside a topology graph. Instead of scanning rows of log data, analysts can see when activity happened and where alerts sit within the wider pattern.

The graph shows the systems and external destinations involved, and hovering over a node highlights its corresponding item in the timeline. Likewise, hovering over an item in the timeline highlights the corresponding route in the topology view. This helps analysts connect a moment in time with the machines, IP addresses or websites involved.

Using a KronoGraph time series chart, the continuous view of time series data makes it really easy to see where the CPU and memory usage spiked (together with the alert), and it guides the user where exactly they should be zooming in. In this example, the workflow helps analysts examine which external sites were visited before and after a user accessed the "Histon Chop Shop" website.

What you can evaluate

For product and engineering teams, this showcase demonstrates how the SDKs can support forensic analysis of network traffic. It highlights synchronized timeline and topology views, temporal filtering, time series charts, and alert overlays for investigating log data visually.

The workflow supports a core network forensics task: turn timestamped logs into a sequence analysts can follow and then connect suspicious activity to the systems involved.

More from Cambridge Intelligence

See all →

Terms of use

These terms do not alter or supersede any existing agreements between you (or your employer) and us.

By accessing or using any Content you agree to be bound by these Terms of Use. Please review these terms carefully before using the website.

The contents of this website, including but not limited to any text, code samples, API references, schemas, interactive tools, and other materials (collectively, the 'Content'), are made available for informational and internal evaluation purposes only. All intellectual property rights in the Content are reserved. No licence is granted to use the Content for any commercial purpose, or to copy, distribute, modify, reverse-engineer, or incorporate any part of the Content into any product or service, without our prior written consent.

This Content is provided “as is” and “as available,” without any representations, warranties, or guarantees of any kind, whether express or implied, including but not limited to implied warranties of merchantability, fitness for a particular purpose, non-infringement, or accuracy. To the fullest extent permitted by applicable law, we expressly exclude and disclaim all implied warranties, conditions, and other terms that might otherwise be implied.

We disclaim all liability for any loss or damage, whether direct, indirect, incidental, consequential, or otherwise, arising from any reliance placed on the Content or from your use of it, to the fullest extent permitted by applicable law. By continuing to access or use the Content, you acknowledge and agree to these terms.