在網路高成長的時代,網路流量管理人員使用網路流量管理系統時,是非常需要一套好的使用者介面的。而目前現有網路異常流量偵測系統所使用之介面,在實際使用上過於偏向專業技術,且部分訊息無法直接傳遞給使用者,需憑藉經驗才有辦法將系統螢幕上的文字轉換為實際所需要的訊息。因此,本研究主要目的為研究如何改善現有網路異常流量偵測系統的介面,並研究此介面模式在不同的任務情況下,有何不同的影響。 經由現況調查得知有定期狀態檢視、異常通報處理、狀態詢問處理三類主要任務,而使用者需求為改善嚴重度訊息、欄位內容設計、選單層級等三類的改善。在依使用者需求建立本研究實驗用的異常檢視器後,配合任務來比較新舊介面,由客觀效標-任務操作時間、主觀效標-任務操作難易度及欄位功能偏好度來評量。 研究結果顯示,修改介面在執行定期狀態檢視任務時有明顯改善差異,整體而言,修改介面有較好之表現。故對於網路異常流量偵測系統的介面來說:(1)執行定期狀態檢視任務時,嚴重度訊息以百分比方式直接呈現其效果優於以實際流量方式呈現。(2)執行定期狀態檢視任務時,主頁面(異常檢視器頁面)應直接顯示是否可實施異常緩解策略及異常策略是否已實施,並可直接連結至異常緩解策略頁面。(3)主頁面(異常檢視器頁面)應可直接點選進入處理記錄備註欄。
To manage the growing complexity of a large-scale network, the Anomaly Traffic Detection System is very useful to locate malicious attacks from Internet. While using such a system, the user-friendly interfaces are very important for increasing work efficiency. Thus, this research focuses on improving the user interfaces of Anomaly Console of current Anomaly Detection system and studying the influence of new interfaces on different missions and tasks. The method of this research includes surveys on current situation, building enhanced Anomaly Console for experiments and comparing the interfaces of them. According to the results of surveys, general missions in an Anomaly Detection system are Console Review, Problem Solving, and Issue Tracking. The effective improvements derived from users’ needs are 1) Highlight the severity information, 2) Give suitable layout and data fields, and 3) Simplify link architecture of web pages. After building the enhanced Anomaly Console for experiments, the researcher compared the original console and new console with objective evaluation of completion time of tasks, subjective evaluation of task difficulty, and subjective preference of information layout. Results of this study show that the modified console has significant influence on mission of Console Reviewing. Generally speaking, the modified interfaces have better evaluation. Consequently, in the aspect of how to improve interfaces of current Anomaly Traffic Detection System, (1) present the ‘Severity’ indicator in percentage is better than in traffic amount, while reviewing the anomaly console. (2) Display information, status and link of mitigation action on main page, while reviewing the anomaly console. (3) On the anomaly console page, put the link to enter the work record (remarks) page directly.