Return
Graph isomorphism network-based intrusion detection method constructed from fixed time-window flow graph
DOI:10.1016/j.comcom.2026.108665.png)
Abstract
En 中文
Network intrusion detection is one of the key technologies for ensuring cybersecurity. In real-world network environments, early detection of attack traffic is crucial. However, existing methods mainly rely on detection after a network flow ends, which limits their timeliness. Moreover, attack traffic disguises itself as normal traffic during the early stages of a connection, exhibiting different attack behaviors across different periods. To address these challenges, this study proposed a fixed time-window flow graph construction-based graph isomorphism network (named FTW-GIN) for intrusion detection. For each bidirectional flow, packets were segmented using fixed time windows. The first N packets within each window were used to construct a graph. These graphs were then trained and classified using GIN. The fixed time-window strategy captured stage-specific attack features by characterizing behavioral variations of bidirectional flows across different time segments. Comparative experiments were conducted on the CICIDS2017 and CICDDoS2019 datasets using different methods. The experimental results showed that FTW-GIN achieved 99.84% Accuracy, 98.06% Precision, 95.16% Recall, and 96.16% F1-score on CICIDS2017, demonstrating superior overall performance compared with most baseline methods.
Keywords:
Network intrusion detection
Cybersecurity
Early detection
Fixed time window
Graph construction
Graph isomorphism network (GIN)
Journal
IF:
4.3
Papers:
592
Citations:
1.1W
Organization
No organization information available
Cited Papers
No cited papers available

