arrow
返回

Practical Cyber Attack Detection With Continuous Temporal Graph in Dynamic Network System

delete2024-01-01
delete1
PRE
AI
G
Guanghan Duan
吕
吕宏武 (Hongwu Lv) *
王会强 封面图
王会强 (Huiqiang Wang)
冯
冯光升 (Guangsheng Feng)
Xiaoli Li 封面图
Xiaoli Li (Xiaoli Li)
DOI:10.1109/TIFS.2024.3385321delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Deep learning (DL) greatly enhances cyber anomaly detection capabilities through effective statistical network characteristic. However, previous methods have not fully addressed two real-world scenario-driven challenges. 1) Frequent node access and disconnection sourced from free-bounded 5G/B5G cyberspace introduce unfamiliar communication behavior patterns, reducing the detection ability of the pre-trained DL model. 2) Low-frequency or sporadic communication behaviors lack stable patterns, posing a challenge for existing AI-driven models, including DL-based detection methods. To address these issues, we propose a cyber anomaly detection framework based on Continuous Temporal Graph (CTG) neural network from a new interaction-centered perspective. The proposed framework refines the concrete information interaction between network entities into the CTG evolution process, thereby naturally incorporating new node access behaviors into feature extraction on CTG neural network. We furthermore present a message aggregation scheme on CTG with fusion of spatio-temporal neighborhood, the actual time distribution and the historical state, thus transforming communication into a more stable pattern for the learning of low-frequency interactions. Extensive experiments on 4 novel datasets, including ToN-IoT, UNSWNB15, CIC-Dark2020, J.P. Morgan payment, demonstrate that our approach outperforms state-of-the-art methods, particularly in detecting new access and low-frequency behaviors.
Keyword:
Anomaly detection
Feature extraction
Network topology
Intrusion detection
Topology
Cyberspace
Industrial Internet of Things
Graph neural network
intrusion detection
anomaly detection
semisupervised learning

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.3K
被引数:
2.3W

机构

H
Harbin Engineering University
学者数:
1.9W
论文数: 1.3W
被引数: 1.3W
A
agency for science technology & research (a*star)
学者数:
2.2W
论文数: 1.9W
被引数: 57
引用论文

引用论文

Role of an indole alkaloid in the resistance of barley seedlings to aphids
err1985-01-01
err0
PREAI
errGustavo E. Zúǹiga; Mabel S. Salgado; Luis J Corcuera
err分享
err收藏
Selectivity of neuronal [3H]GABA accumulation in the visual cortex as revealed by Golgi staining of the labeled neurons
err1981-11-01
err0
PREAI
errPe´ter Somogyi; Tama´s F. Freund; Norbert Hala´sz; Zolta´n F. Kisva´rdy
err分享
err收藏
Dendritic mechanisms controlling the threshold and timing requirement of synaptic plasticity
err2011-02-24
err0
PREAI
errCuiping Zhao; Lang Wang; Theoden Netoff; Li‐Lian Yuan
err分享
err收藏
A Survey of Public IoT Datasets for Network Security Research
err2023-01-01
err17
PREAI
errDe Keersmaeker, Francois; Cao, Yinan; Ndonda, Gorby Kabasele; Sadre, Ramin
err分享
err收藏
err分享
err收藏
学者 查看更多内容