Graph Autoencoders for Detecting Anomalous Intrusions in OT Networks Through Dynamic Link Detection

被引:0
|
作者
Howe, Alex [1 ]
Peasley, Dale [1 ]
Papa, Mauricio [1 ]
机构
[1] Univ Tulsa, Tulsa, OK 74104 USA
关键词
D O I
10.1109/CCNC51664.2024.10454841
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper evaluates the use of graph neural network (GNN) based autoencoders for detecting network intrusions or anomalous traffic in Operational Technology (OT) networks. Traditional intrusion detection methods often struggle to capture the complex relationships and interdependencies found in OT network communications. These spatial relationships can provide information vital for identifying harder to detect attacks (i.e. Advanced Persistent Threats). GNNs are a machine learning technique which operate on graph-structured data and can be used to identify underlying patterns and relationships between the nodes. Graph autoencoders (GAEs) are an unsupervised GNN-based learning technique that incorporates an encoder-decoder architecture and can be used for anomaly detection in graph structured data. This work evaluates the use of graph autoencoders for detecting anomalous edges (extracted from packets) in OT network data. Additionally, we introduce a method for encoding raw network traffic into discrete temporal graphs which can be used to apply GAEs for real-time intrusion detection. The proposed network traffic encoding scheme incorporates multi-dimensional edge attributes in order to capture information for determining the relevance of a given network packet. The approach is evaluated using two OT network datasets each containing labeled examples of commonly encountered malicious attack traffic. Results are compared against baseline anomaly detection methods including K-Nearest Neighbors, Deep Autoencoders, and Isolation Forest. The proposed graph autoencoder outperforms the baseline cases in terms of detection accuracy achieving a 31.05% and 8.64% improvement in F1 scores over the baseline models on the two OT network datasets.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Anomaly Detection with Deep Graph Autoencoders on Attributed Networks
    Zhu, Dali
    Ma, Yuchen
    Liu, Yinlong
    2020 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2020, : 749 - 754
  • [2] Anomalous Communications Detection in IoT Networks Using Sparse Autoencoders
    Shahid, Mustafizur R.
    Blanc, Gregory
    Zhang, Zonghua
    Debar, Herve
    2019 IEEE 18TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2019, : 165 - 169
  • [3] Using Graph Neural Networks for the Detection and Explanation of Network Intrusions
    Baahmed, Ahmed Rafik El-Mehdi
    Andresini, Giuseppina
    Robardet, Celine
    Appice, Annalisa
    MACHINE LEARNING AND PRINCIPLES AND PRACTICE OF KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2023, PT III, 2025, 2135 : 201 - 216
  • [4] Exploring Graph Centralities for Detecting Anomalous Behavior in Large Networks
    Rastogi, Nidhi
    Hendler, James
    TRUST AND TRUSTWORTHY COMPUTING, TRUST 2015, 2015, 9229 : 323 - 324
  • [5] Detecting Anomalous Activity on Networks With the Graph Fourier Scan Statistic
    Sharpnack, James
    Rinaldo, Alessandro
    Singh, Aarti
    IEEE TRANSACTIONS ON SIGNAL PROCESSING, 2016, 64 (02) : 364 - 379
  • [6] Modularity-aware graph autoencoders for joint community detection and link prediction
    Salha-Galvan, Guillaume
    Lutzeyer, Johannes F.
    Dasoulas, George
    Hennequin, Romain
    Vazirgiannis, Michalis
    NEURAL NETWORKS, 2022, 153 : 474 - 495
  • [7] RGSE: Robust Graph Structure Embedding for Anomalous Link Detection
    Liu, Zhen
    Zuo, Wenbo
    Zhang, Dongning
    Feng, Xiaodong
    IEEE TRANSACTIONS ON BIG DATA, 2023, 9 (05) : 1420 - 1429
  • [8] Detecting Anomalous Network Communication Patterns Using Graph Convolutional Networks
    Vaisman, Yizhak
    Katz, Gilad
    Elovici, Yuval
    Shabtai, Asaf
    arXiv, 2023,
  • [9] Graph Neural Networks Based Anomalous RSSI Detection
    Bertalanic, Blaz
    Vnucec, Matej
    Fortuna, Carolina
    2023 INTERNATIONAL BALKAN CONFERENCE ON COMMUNICATIONS AND NETWORKING, BALKANCOM, 2023,
  • [10] Anomalous Node Detection in Blockchain Networks Based on Graph Neural Networks
    Chang, Ze
    Cai, Yunfei
    Liu, Xiao Fan
    Xie, Zhenping
    Liu, Yuan
    Zhan, Qianyi
    SENSORS, 2025, 25 (01)