Graph Neural Networks for Intrusion Detection: A Survey
Графовые нейронные сети для обнаружения вторжений: обзор
2023-01-01
SCID: 54.1/u972qsnv
Discuss with AI
Graph neural networksGraph representation learningIntrusion detectionNetwork flow graphsProvenance graphs
Figures from the paper
Abstract (AI)
Cyberattacks represent an ever-growing threat that has become a real priority for most organizations. Attackers use sophisticated attack scenarios to deceive defense systems in order to access private data or cause harm. Machine Learning (ML) and Deep Learning (DL) have demonstrate impressive results for detecting cyberattacks due to their ability to learn generalizable patterns from flat data. However, flat data fail to capture the structural behavior of attacks, which is essential for effective detection. Contrarily, graph structures provide a more robust and abstract view of a system that is difficult for attackers to evade. Recently, Graph Neural Networks (GNNs) have become successful in learning useful representations from the semantic provided by graph-structured data. Intrusions have been detected for years using graphs such as network flow graphs or provenance graphs, and learning representations from these structures can help models understand the structural patterns of attacks, in addition to traditional features. In this survey, we focus on the applications of graph representation learning to the detection of network-based and host-based intrusions, with special attention to GNN methods. For both network and host levels, we present the graph data structures that can be leveraged and we comprehensively review the state-of-the-art papers along with the used datasets. Our analysis reveals that GNNs are particularly efficient in cybersecurity, since they can learn effective representations without requiring any external domain knowledge. We also evaluate the robustness of these techniques based on adversarial attacks. Finally, we discuss the strengths and weaknesses of GNN-based intrusion detection and identify future research directions.
Key Findings
1
Flat data often fail to capture the structural behavior of cyberattacks, whereas graph representations provide a more robust and abstract view of systems.
2
Graph Neural Networks can learn attack-relevant representations from network-flow and provenance graphs, complementing traditional intrusion-detection features.
3
The analysis indicates that GNNs are particularly effective for cybersecurity because they learn useful representations without requiring external domain knowledge.
4
The survey evaluates GNN-based intrusion detection robustness against adversarial attacks and identifies associated strengths, weaknesses, and future research directions.
5
The survey reviews graph representation learning for both network-based and host-based intrusion detection, including graph structures, state-of-the-art methods, and datasets.
Research Object
Network-based and host-based intrusion detection systems and their graph-structured representations
Research Subject
graph representation learning, particularly Graph Neural Network methods, for detecting intrusions and their robustness to adversarial attacks
Publication Details
Publication Date
2023-01-01
Journal
Publisher
ISSN
Cited by
220
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest
References available in scid.ai5
The Graph Neural Network Model2008
Targeted Branching for the Maximum Independent Set Problem Using Graph Neural Networks2024
Heterogeneous Graph Attention Network2019
Neural Message Passing for Quantum Chemistry2017
Machine Learning and Deep Learning Methods for Intrusion Detection Systems: A Survey2019