Abstract:In recent years, the network security log data shows explosive growth. However, the existing visualization technology is hardly to support the analysis of high dimensional and multi-granularity NetFlow log data. In order to make advantages of the visualization technology, this study proposes a new network security visualization framework to paint the picture, uses the three dimensional histogram which help users to quickly master the abnormal moment of network shown by the Netflow log data, uses information entropy algorithm to process multi-dimensional data, makes use of the matrix chart, bubble diagram, and line chart to synthesize analyzed data in detail. Finally, we carry out an experiment to test the process of DDOS attack, and Port Scanning Attack can be detected easily by proposed system. The study proves that the system which has rich visual graphics and provides simple collaborative interaction can better help network security personnel to analyze the entire network behavior process.