XG-BoT: An Explainable Deep Graph Neural Network for Botnet Detection and Forensics

07/19/2022
by   Wai Weng Lo, et al.
0

In this paper, we proposed XG-BoT, an explainable deep graph neural network model for botnet node detection. The proposed model is mainly composed of a botnet detector and an explainer for automatic forensics. The XG-BoT detector can effectively detect malicious botnet nodes under large-scale networks. Specifically, it utilizes a grouped reversible residual connection with a graph isomorphism network to learn expressive node representations from the botnet communication graphs. The explainer in XG-BoT can perform automatic network forensics by highlighting suspicious network flows and related botnet nodes. We evaluated XG-BoT on real-world, large-scale botnet network graphs. Overall, XG-BoT is able to outperform the state-of-the-art in terms of evaluation metrics. In addition, we show that the XG-BoT explainer can generate useful explanations based on GNNExplainer for automatic network forensics.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/26/2021

Towards Self-Explainable Graph Neural Network

Graph Neural Networks (GNNs), which generalize the deep neural networks ...
research
10/09/2020

Meta Graph Attention on Heterogeneous Graph with Node-Edge Co-evolution

Graph neural networks have become an important tool for modeling structu...
research
11/24/2020

xFraud: Explainable Fraud Transaction Detection on Heterogeneous Graphs

At online retail platforms, it is crucial to actively detect risks of fr...
research
12/31/2022

UltraProp: Principled and Explainable Propagation on Large Graphs

Given a large graph with few node labels, how can we (a) identify the mi...
research
05/30/2019

Graph Normalizing Flows

We introduce graph normalizing flows: a new, reversible graph neural net...
research
07/22/2019

Deep Learning Assisted Sum-Product Detection Algorithm for Faster-than-Nyquist Signaling

A deep learning assisted sum-product detection algorithm (DL-SPA) for fa...
research
03/17/2023

High Accurate and Explainable Multi-Pill Detection Framework with Graph Neural Network-Assisted Multimodal Data Fusion

Due to the significant resemblance in visual appearance, pill misuse is ...

Please sign up or login with your details

Forgot password? Click here to reset