arrow
Return

Practical Cyber Attack Detection With Continuous Temporal Graph in Dynamic Network System

delete2024-01-01
delete1
PRE
AI
G
Guanghan Duan
吕宏武 (Hongwu Lv) *
王会强 cover
王会强 (Huiqiang Wang)
冯光升 (Guangsheng Feng)
X
Xiaoli Li
DOI:10.1109/TIFS.2024.3385321delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Deep learning (DL) greatly enhances cyber anomaly detection capabilities through effective statistical network characteristic. However, previous methods have not fully addressed two real-world scenario-driven challenges. 1) Frequent node access and disconnection sourced from free-bounded 5G/B5G cyberspace introduce unfamiliar communication behavior patterns, reducing the detection ability of the pre-trained DL model. 2) Low-frequency or sporadic communication behaviors lack stable patterns, posing a challenge for existing AI-driven models, including DL-based detection methods. To address these issues, we propose a cyber anomaly detection framework based on Continuous Temporal Graph (CTG) neural network from a new interaction-centered perspective. The proposed framework refines the concrete information interaction between network entities into the CTG evolution process, thereby naturally incorporating new node access behaviors into feature extraction on CTG neural network. We furthermore present a message aggregation scheme on CTG with fusion of spatio-temporal neighborhood, the actual time distribution and the historical state, thus transforming communication into a more stable pattern for the learning of low-frequency interactions. Extensive experiments on 4 novel datasets, including ToN-IoT, UNSWNB15, CIC-Dark2020, J.P. Morgan payment, demonstrate that our approach outperforms state-of-the-art methods, particularly in detecting new access and low-frequency behaviors.
Keywords:
Anomaly detection
Feature extraction
Network topology
Intrusion detection
Topology
Cyberspace
Industrial Internet of Things
Graph neural network
intrusion detection
anomaly detection
semisupervised learning

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

H
Harbin Engineering University
Scholars:
1.9W
Papers: 1.3W
Citations: 1.3W
A
agency for science technology & research (a*star)
Scholars:
2.2W
Papers: 1.9W
Citations: 57