Graph Autoencoders for Detecting Anomalous Intrusions in OT Networks Through Dynamic Link Detection

被引:0
|
作者
Howe, Alex [1 ]
Peasley, Dale [1 ]
Papa, Mauricio [1 ]
机构
[1] Univ Tulsa, Tulsa, OK 74104 USA
关键词
D O I
10.1109/CCNC51664.2024.10454841
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper evaluates the use of graph neural network (GNN) based autoencoders for detecting network intrusions or anomalous traffic in Operational Technology (OT) networks. Traditional intrusion detection methods often struggle to capture the complex relationships and interdependencies found in OT network communications. These spatial relationships can provide information vital for identifying harder to detect attacks (i.e. Advanced Persistent Threats). GNNs are a machine learning technique which operate on graph-structured data and can be used to identify underlying patterns and relationships between the nodes. Graph autoencoders (GAEs) are an unsupervised GNN-based learning technique that incorporates an encoder-decoder architecture and can be used for anomaly detection in graph structured data. This work evaluates the use of graph autoencoders for detecting anomalous edges (extracted from packets) in OT network data. Additionally, we introduce a method for encoding raw network traffic into discrete temporal graphs which can be used to apply GAEs for real-time intrusion detection. The proposed network traffic encoding scheme incorporates multi-dimensional edge attributes in order to capture information for determining the relevance of a given network packet. The approach is evaluated using two OT network datasets each containing labeled examples of commonly encountered malicious attack traffic. Results are compared against baseline anomaly detection methods including K-Nearest Neighbors, Deep Autoencoders, and Isolation Forest. The proposed graph autoencoder outperforms the baseline cases in terms of detection accuracy achieving a 31.05% and 8.64% improvement in F1 scores over the baseline models on the two OT network datasets.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] A Flexible Attentive Temporal Graph Networks for Anomaly Detection in Dynamic Networks
    Zhu, Dali
    Ma, Yuchen
    Liu, Yinlong
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 871 - 876
  • [22] Detecting Anomalous Events in Object-Centric Business Processes via Graph Neural Networks
    Niro, Alessandro
    Werner, Michael
    PROCESS MINING WORKSHOPS, ICPM 2023, 2024, 503 : 179 - 190
  • [23] Detecting anomalous traffic behaviors with seasonal deep Kalman filter graph convolutional neural networks
    Sun, Yanshen
    Lu, Yen-Cheng
    Fu, Kaiqun
    Chen, Fanglan
    Lu, Chang -Tien
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (08) : 4729 - 4742
  • [24] Detecting Change Processes in Dynamic Networks by Frequent Graph Evolution Rule Mining
    Scharwaechter, Erik
    Mueller, Emmanuel
    Donges, Jonathan
    Hassani, Marwan
    Seidl, Thomas
    2016 IEEE 16TH INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2016, : 1191 - 1196
  • [25] Multivariate graph learning for detecting aberrant connectivity of dynamic brain networks in autism
    Aggarwal, Priya
    Gupta, Anubha
    MEDICAL IMAGE ANALYSIS, 2019, 56 : 11 - 25
  • [26] Graph regularized nonnegative matrix factorization for temporal link prediction in dynamic networks
    Ma, Xiaoke
    Sun, Penggang
    Wang, Yu
    PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2018, 496 : 121 - 136
  • [27] Temporal group-aware graph diffusion networks for dynamic link prediction
    Huang, Da
    Lei, Fangyuan
    INFORMATION PROCESSING & MANAGEMENT, 2023, 60 (03)
  • [28] Temporal graph learning for dynamic link prediction with text in online social networks
    Dileo, Manuel
    Zignani, Matteo
    Gaito, Sabrina
    MACHINE LEARNING, 2024, 113 (04) : 2207 - 2226
  • [29] Temporal graph learning for dynamic link prediction with text in online social networks
    Manuel Dileo
    Matteo Zignani
    Sabrina Gaito
    Machine Learning, 2024, 113 : 2207 - 2226
  • [30] Dynamic networks link prediction based on continuous gated recurrent graph convolution
    Liao, Yunchun
    Shu, Jian
    Liu, Linlan
    INTERNATIONAL JOURNAL OF MACHINE LEARNING AND CYBERNETICS, 2024, : 2653 - 2669