Anomal-E: A Self-Supervised Network Intrusion Detection System based on Graph Neural Networks

07/14/2022
by   Evan Caville, et al.
0

This paper investigates Graph Neural Networks (GNNs) application for self-supervised network intrusion and anomaly detection. GNNs are a deep learning approach for graph-based data that incorporate graph structures into learning to generalise graph representations and output embeddings. As network flows are naturally graph-based, GNNs are a suitable fit for analysing and learning network behaviour. The majority of current implementations of GNN-based Network Intrusion Detection Systems (NIDSs) rely heavily on labelled network traffic which can not only restrict the amount and structure of input traffic, but also the NIDSs potential to adapt to unseen attacks. To overcome these restrictions, we present Anomal-E, a GNN approach to intrusion and anomaly detection that leverages edge features and graph topological structure in a self-supervised process. This approach is, to the best our knowledge, the first successful and practical approach to network intrusion detection that utilises network flows in a self-supervised, edge leveraging GNN. Experimental results on two modern benchmark NIDS datasets not only clearly display the improvement of using Anomal-E embeddings rather than raw features, but also the potential Anomal-E has for detection on wild network traffic.

READ FULL TEXT
research
03/30/2021

E-GraphSAGE: A Graph Neural Network based Intrusion Detection System

This paper presents a new network intrusion detection system (NIDS) base...
research
03/20/2022

Inspection-L: A Self-Supervised GNN-Based Money Laundering Detection System for Bitcoin

Criminals have become increasingly experienced in using cryptocurrencies...
research
07/30/2021

Unveiling the potential of Graph Neural Networks for robust Intrusion Detection

The last few years have seen an increasing wave of attacks with serious ...
research
11/26/2021

Graph-based Solutions with Residuals for Intrusion Detection: the Modified E-GraphSAGE and E-ResGAT Algorithms

The high volume of increasingly sophisticated cyber threats is drawing g...
research
04/07/2023

BS-GAT Behavior Similarity Based Graph Attention Network for Network Intrusion Detection

With the development of the Internet of Things (IoT), network intrusion ...
research
04/20/2021

GDDR: GNN-based Data-Driven Routing

We explore the feasibility of combining Graph Neural Network-based polic...
research
06/14/2022

RoSGAS: Adaptive Social Bot Detection with Reinforced Self-Supervised GNN Architecture Search

Social bots are referred to as the automated accounts on social networks...

Please sign up or login with your details

Forgot password? Click here to reset