arrow
Return

Graph isomorphism network-based intrusion detection method constructed from fixed time-window flow graph

delete2026-09-06
delete0
PRE
AI
Y
Yao Tan
H
Haiyan Fu *
S
Shenghui Wu
DOI:10.1016/j.comcom.2026.108665delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Network intrusion detection is one of the key technologies for ensuring cybersecurity. In real-world network environments, early detection of attack traffic is crucial. However, existing methods mainly rely on detection after a network flow ends, which limits their timeliness. Moreover, attack traffic disguises itself as normal traffic during the early stages of a connection, exhibiting different attack behaviors across different periods. To address these challenges, this study proposed a fixed time-window flow graph construction-based graph isomorphism network (named FTW-GIN) for intrusion detection. For each bidirectional flow, packets were segmented using fixed time windows. The first N packets within each window were used to construct a graph. These graphs were then trained and classified using GIN. The fixed time-window strategy captured stage-specific attack features by characterizing behavioral variations of bidirectional flows across different time segments. Comparative experiments were conducted on the CICIDS2017 and CICDDoS2019 datasets using different methods. The experimental results showed that FTW-GIN achieved 99.84% Accuracy, 98.06% Precision, 95.16% Recall, and 96.16% F1-score on CICIDS2017, demonstrating superior overall performance compared with most baseline methods.
Keywords:
Network intrusion detection
Cybersecurity
Early detection
Fixed time window
Graph construction
Graph isomorphism network (GIN)

Journal

Computer Communications cover
Computer Communications
IF:
4.3
Papers:
592
Citations:
1.1W

Organization

No organization information available
Cited Papers

Cited Papers

No cited papers available