Graph Autoencoders for Detecting Anomalous Intrusions in OT Networks Through Dynamic Link Detection

被引:0
|
作者
Howe, Alex [1 ]
Peasley, Dale [1 ]
Papa, Mauricio [1 ]
机构
[1] Univ Tulsa, Tulsa, OK 74104 USA
关键词
D O I
10.1109/CCNC51664.2024.10454841
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper evaluates the use of graph neural network (GNN) based autoencoders for detecting network intrusions or anomalous traffic in Operational Technology (OT) networks. Traditional intrusion detection methods often struggle to capture the complex relationships and interdependencies found in OT network communications. These spatial relationships can provide information vital for identifying harder to detect attacks (i.e. Advanced Persistent Threats). GNNs are a machine learning technique which operate on graph-structured data and can be used to identify underlying patterns and relationships between the nodes. Graph autoencoders (GAEs) are an unsupervised GNN-based learning technique that incorporates an encoder-decoder architecture and can be used for anomaly detection in graph structured data. This work evaluates the use of graph autoencoders for detecting anomalous edges (extracted from packets) in OT network data. Additionally, we introduce a method for encoding raw network traffic into discrete temporal graphs which can be used to apply GAEs for real-time intrusion detection. The proposed network traffic encoding scheme incorporates multi-dimensional edge attributes in order to capture information for determining the relevance of a given network packet. The approach is evaluated using two OT network datasets each containing labeled examples of commonly encountered malicious attack traffic. Results are compared against baseline anomaly detection methods including K-Nearest Neighbors, Deep Autoencoders, and Isolation Forest. The proposed graph autoencoder outperforms the baseline cases in terms of detection accuracy achieving a 31.05% and 8.64% improvement in F1 scores over the baseline models on the two OT network datasets.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] Anomalous behavior detection based on optimized graph embedding representation in social networks
    Xing, Ling
    Li, Shiyu
    Zhang, Qi
    Wu, Honghai
    Ma, Huahong
    Zhang, Xiaohui
    JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2024, 36 (07)
  • [32] A Graph Construction Method for Anomalous Traffic Detection with Graph Neural Networks Using Sets of Flow Data
    Okui, Norihiro
    Akimoto, Yusuke
    Kubota, Ayumu
    Yoshida, Takuya
    2023 IEEE 47TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE, COMPSAC, 2023, : 1017 - 1018
  • [33] Dynamic Networks Analysis and Visualization through Spatiotemporal Link Segmentation
    Li, Ting
    Liao, Qi
    PROCEEDINGS OF 2016 IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND BIG DATA ANALYSIS (ICCCBDA 2016), 2016, : 209 - 214
  • [34] A community detection algorithm for dynamic networks using link clustering
    Dong, Zhe
    Yi, Peng
    Hsi-An Chiao Tung Ta Hsueh/Journal of Xi'an Jiaotong University, 2014, 48 (08): : 73 - 79
  • [35] Subtle Anomaly Detection in Dynamic Networks using Graph Spectra
    Wang, Xiaoyu
    Zhou, Yongwang
    Li, Dongbiao
    Zhang, Chi
    2024 IEEE/CIC INTERNATIONAL CONFERENCE ON COMMUNICATIONS IN CHINA, ICCC, 2024,
  • [36] Graph Neural Network Based Anomaly Detection in Dynamic Networks
    Guo J.-Y.
    Li R.-H.
    Zhang Y.
    Wang G.-R.
    Ruan Jian Xue Bao/Journal of Software, 2020, 31 (03): : 748 - 762
  • [37] Anomalous distributed traffic: Detecting cyber security attacks amongst microservices using graph convolutional networks
    Jacob, Stephen
    Qiao, Yuansong
    Ye, Yuhang
    Lee, Brian
    COMPUTERS & SECURITY, 2022, 118
  • [38] Social Media Rumour Detection Through Graph Attention Networks
    Zhang, Xinpeng
    Gong, Shuzhi
    Sinnott, Richard O.
    2021 IEEE ASIA-PACIFIC CONFERENCE ON COMPUTER SCIENCE AND DATA ENGINEERING (CSDE), 2021,
  • [39] Dynamic network link prediction with node representation learning from graph convolutional networks
    Mei, Peng
    Zhao, Yu Hong
    SCIENTIFIC REPORTS, 2024, 14 (01)
  • [40] Dynamic network link prediction with node representation learning from graph convolutional networks
    Peng Mei
    Yu hong Zhao
    Scientific Reports, 14