GNN-IDS: Graph Neural Network based Intrusion Detection System
GNN-IDS: система обнаружения вторжений на основе графовой нейронной сети
2024-07-25
SCID: 54.1/4une2ww3
Discuss with AI
attack graphexplainabilitygraph neural networkintrusion detection systemnetwork anomaly detection
Figures from the paper
Abstract (AI)
Intrusion detection systems (IDSs) are widely used to identify anomalies in computer networks and raise alarms on intrusive behaviors. ML-based IDSs generally take network traces or host logs as input to extract patterns from individual samples, whereas the inter-dependencies of network are often not captured and learned, which may result in large amounts of uncertain predictions, false positives, and false negatives. To tackle the challenges in intrusion detection, we propose a graph neural network-based intrusion detection system (GNN-IDS), which is data-driven and machine learning-empowered. In our proposed GNN-IDS, the attack graph and real-time measurements that represent static and dynamic attributes of computer networks, respectively, are incorporated and associated to represent complex computer networks. Graph neural networks are employed as the inference engine for intrusion detection. By learning network connectivity, graph neural networks can quantify the importance of neighboring nodes and node features to make more reliable predictions. Furthermore, by incorporating an attack graph, GNN-IDS could not only detect anomalies but also identify the malicious actions causing the anomalies. The experimental results on a use case network with two synthetic datasets (one generated from public IDS data) show that the proposed GNN-IDS achieves good performance. The results are analyzed from the aspects of uncertainty, explainability, and robustness.
Key Findings
1
Experiments on a use-case network with two synthetic datasets, including one generated from public IDS data, demonstrate good performance.
2
GNN-IDS integrates static attack graphs with real-time network measurements to represent complex computer networks for intrusion detection.
3
Graph neural networks learn network connectivity and quantify neighboring-node and node-feature importance, enabling more reliable intrusion predictions.
4
Incorporating attack graphs allows GNN-IDS to identify malicious actions causing detected anomalies, beyond anomaly detection alone.
5
The evaluation analyzes GNN-IDS in terms of prediction uncertainty, explainability, and robustness.
Research Object
Computer networks represented by attack graphs and real-time measurements for intrusion detection
Research Subject
Graph-based detection and identification of malicious network actions, with improved prediction reliability, uncertainty, explainability, and robustness
Publication Details
Publication Date
2024-07-25
Journal
Publisher
ISSN
Cited by
66
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest