GNN-Based Network Traffic Analysis for the Detection of Sequential Attacks in IoT

被引:2
|
作者
Altaf, Tanzeela [1 ]
Wang, Xu [1 ]
Ni, Wei [2 ]
Yu, Guangsheng [2 ]
Liu, Ren Ping [1 ]
Braun, Robin [1 ]
机构
[1] Univ Technol Sydney, Sch Elect & Data Engn, Sydney, NSW 2007, Australia
[2] CSIRO, Data61, Sydney, NSW 2122, Australia
关键词
graph neural networks (GNNs); IoT security; sequential attacks; botnet detection; intrusion detection systems (IDSs); temporal dynamics;
D O I
10.3390/electronics13122274
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This research introduces a novel framework utilizing a sequential gated graph convolutional neural network (GGCN) designed specifically for botnet detection within Internet of Things (IoT) network environments. By capitalizing on the strengths of graph neural networks (GNNs) to represent network traffic as complex graph structures, our approach adeptly handles the temporal dynamics inherent to botnet attacks. Key to our approach is the development of a time-stamped multi-edge graph structure that uncovers subtle temporal patterns and hidden relationships in network flows, critical for recognizing botnet behaviors. Moreover, our sequential graph learning framework incorporates time-sequenced edges and multi-edged structures into a two-layered gated graph model, which is optimized with specialized message-passing layers and aggregation functions to address the challenges of time-series traffic data effectively. Our comparative analysis with the state of the art reveals that our sequential gated graph convolutional neural network achieves substantial improvements in detecting IoT botnets. The proposed GGCN model consistently outperforms the conventional model, achieving improvements in accuracy ranging from marginal to substantial-0.01% for BoT IoT and up to 25% for Mirai. Moreover, our empirical analysis underscores the GGCN's enhanced capabilities, particularly in binary classification tasks, on imbalanced datasets. These findings highlight the model's ability to effectively navigate and manage the varying complexity and characteristics of IoT security threats across different datasets.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] Efficient Network Representation for GNN-Based Intrusion Detection
    Friji, Hamdi
    Olivereau, Alexis
    Sarkiss, Mireille
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, PT I, ACNS 2023, 2023, 13905 : 532 - 554
  • [2] Contrastive GNN-based Traffic Anomaly Analysis Against Imbalanced Dataset in IoT-based ITS
    Wang, Yang
    Lin, Xi
    Wu, Jun
    Bashir, Ali Kashif
    Yang, Wu
    Li, Jianhua
    Imran, Muhammad
    2022 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2022), 2022, : 3557 - 3562
  • [3] Membership Inference Attacks against GNN-based Hardware Trojan Detection
    Hasegawa, Kento
    Yamashita, Kazuki
    Hidano, Seira
    Fukushima, Kazuhide
    Hashimoto, Kazuo
    Togawa, Nozomu
    2023 IEEE 22ND INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS, TRUSTCOM, BIGDATASE, CSE, EUC, ISCI 2023, 2024, : 1222 - 1229
  • [4] Discerning Limitations of GNN-based Attacks on Logic Locking
    Darjani, Armin
    Kavand, Nima
    Rai, Shubham
    Kumar, Akash
    2023 60TH ACM/IEEE DESIGN AUTOMATION CONFERENCE, DAC, 2023,
  • [5] Targeted Shilling Attacks on GNN-based Recommender Systems
    Guo, Sihan
    Bai, Ting
    Deng, Weihong
    PROCEEDINGS OF THE 32ND ACM INTERNATIONAL CONFERENCE ON INFORMATION AND KNOWLEDGE MANAGEMENT, CIKM 2023, 2023, : 649 - 658
  • [6] Thwarting GNN-Based Attacks Against Logic Locking
    Darjani, Armin
    Kavand, Nima
    Rai, Shubham
    Kumar, Akash
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 7200 - 7215
  • [7] MS2-GNN: Exploring GNN-Based Multimodal Fusion Network for Depression Detection
    Chen, Tao
    Hong, Richang
    Guo, Yanrong
    Hao, Shijie
    Hu, Bin
    IEEE TRANSACTIONS ON CYBERNETICS, 2023, 53 (12) : 7749 - 7759
  • [8] Label-Flipping Attacks in GNN-Based Federated Learning
    Yu, Shanqing
    Shen, Jie
    Xu, Shaocong
    Wang, Jinhuan
    Wang, Zeyu
    Xuan, Qi
    IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2025, 12 (02): : 1357 - 1368
  • [9] Traffexplainer: A Framework Toward GNN-Based Interpretable Traffic Prediction
    Kong, Lingbai
    Yang, Hanchen
    Li, Wengen
    Zhang, Yichao
    Guan, Jihong
    Zhou, Shuigeng
    IEEE Transactions on Artificial Intelligence, 2025, 6 (03): : 559 - 573
  • [10] Interpreters for GNN-Based Vulnerability Detection: Are We There Yet?
    Hu, Yutao
    Wang, Suyuan
    Li, Wenke
    Peng, Junru
    Wu, Yueming
    Zou, Deqing
    Jin, Hai
    PROCEEDINGS OF THE 32ND ACM SIGSOFT INTERNATIONAL SYMPOSIUM ON SOFTWARE TESTING AND ANALYSIS, ISSTA 2023, 2023, : 1407 - 1419