Admin should see the map + a table containing the list of local devices (obtained through listing arp table) These devices should be named and monitored by some IDS (Suricata ?). Detection of a compromised device should be displayed in this table.