GNN-IDS: Graph Neural Network based Intrusion Detection System

GNN-IDS: система обнаружения вторжений на основе графовой нейронной сети
Zhuo Sun, André Teixeira, Salman Toor
2024-07-25

attack graphexplainabilitygraph neural networkintrusion detection systemnetwork anomaly detection
Intrusion detection systems (IDSs) are widely used to identify anomalies in computer networks and raise alarms on intrusive behaviors. ML-based IDSs generally take network traces or host logs as input to extract patterns from individual samples, whereas the inter-dependencies of network are often not captured and learned, which may result in large amounts of uncertain predictions, false positives, and false negatives. To tackle the challenges in intrusion detection, we propose a graph neural network-based intrusion detection system (GNN-IDS), which is data-driven and machine learning-empowered. In our proposed GNN-IDS, the attack graph and real-time measurements that represent static and dynamic attributes of computer networks, respectively, are incorporated and associated to represent complex computer networks. Graph neural networks are employed as the inference engine for intrusion detection. By learning network connectivity, graph neural networks can quantify the importance of neighboring nodes and node features to make more reliable predictions. Furthermore, by incorporating an attack graph, GNN-IDS could not only detect anomalies but also identify the malicious actions causing the anomalies. The experimental results on a use case network with two synthetic datasets (one generated from public IDS data) show that the proposed GNN-IDS achieves good performance. The results are analyzed from the aspects of uncertainty, explainability, and robustness.
1
Experiments on a use-case network with two synthetic datasets, including one generated from public IDS data, demonstrate good performance.
2
GNN-IDS integrates static attack graphs with real-time network measurements to represent complex computer networks for intrusion detection.
3
Graph neural networks learn network connectivity and quantify neighboring-node and node-feature importance, enabling more reliable intrusion predictions.
4
Incorporating attack graphs allows GNN-IDS to identify malicious actions causing detected anomalies, beyond anomaly detection alone.
5
The evaluation analyzes GNN-IDS in terms of prediction uncertainty, explainability, and robustness.

Computer networks represented by attack graphs and real-time measurements for intrusion detection

Graph-based detection and identification of malicious network actions, with improved prediction reliability, uncertainty, explainability, and robustness

Publication Details
Publication Date
2024-07-25
Journal
Publisher
ISSN
Cited by
66
Access Type
Author Information
Authors
Zhuo Sun
André Teixeira
Salman Toor
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%