Network Flow Based IoT Anomaly Detection Using Graph Neural Network

被引:0
|
作者
Wei, Chongbo [1 ,2 ]
Xie, Gaogang [3 ]
Diao, Zulong [1 ,4 ]
机构
[1] Chinese Acad Sci, Inst Comp Technol, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Beijing, Peoples R China
[3] Chinese Acad Sci, Comp Network Informat Ctr, Beijing, Peoples R China
[4] Purple Mt Labs, Nanjing, Peoples R China
基金
中国国家自然科学基金;
关键词
Deep learning; Anomaly detection; Internet-of-things; Network flow; Graph neural network;
D O I
10.1007/978-3-031-40286-9_35
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep learning-based traffic anomaly detection methods are usually fed with high-dimensional statistical features. The greatest challenges are how to detect complex inter-feature relationships and localize and explain anomalies that deviate from these relationships. However, existing methods do not explicitly learn the structure of existing relationships between traffic features or use them to predict the expected behavior of traffic. In this work, we propose a network flow-based IoT anomaly detection approach. It extracts traffic features in different channels as time series. Then a graph neural network combined with a structure learning approach is used to learn relationships between features, which allows users to deduce the root cause of a detected anomaly. We build a real IoT environment and deploy our method on a gateway (simulated with Raspberry PI). The experiment results show that our method has excellent accuracy for detecting anomaly activities and localizes and explains these deviations.
引用
收藏
页码:432 / 445
页数:14
相关论文
共 50 条
  • [1] Network Anomaly Detection Using a Graph Neural Network
    Kisanga, Patrice
    Woungang, Isaac
    Traore, Issa
    Carvalho, Glaucio H. S.
    [J]. 2023 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2023, : 61 - 65
  • [2] A graph neural network method for distributed anomaly detection in IoT
    Protogerou, Aikaterini
    Papadopoulos, Stavros
    Drosou, Anastasios
    Tzovaras, Dimitrios
    Refanidis, Ioannis
    [J]. EVOLVING SYSTEMS, 2021, 12 (01) : 19 - 36
  • [3] A graph neural network method for distributed anomaly detection in IoT
    Aikaterini Protogerou
    Stavros Papadopoulos
    Anastasios Drosou
    Dimitrios Tzovaras
    Ioannis Refanidis
    [J]. Evolving Systems, 2021, 12 : 19 - 36
  • [4] Anomaly Detection Using Deep Neural Network for IoT Architecture
    Ahmad, Zeeshan
    Khan, Adnan Shahid
    Nisar, Kashif
    Haider, Iram
    Hassan, Rosilah
    Haque, Muhammad Reazul
    Tarmizi, Seleviawati
    Rodrigues, Joel J. P. C.
    [J]. APPLIED SCIENCES-BASEL, 2021, 11 (15):
  • [5] Enhancing Network Anomaly Detection Using Graph Neural Networks
    Marfo, William
    Tosh, Deepak K.
    Moore, Shirley V.
    [J]. 2024 22ND MEDITERRANEAN COMMUNICATION AND COMPUTER NETWORKING CONFERENCE, MEDCOMNET 2024, 2024,
  • [6] Anomaly detection of traffic session based on graph neural network
    Du Peng
    Peng Cheng-Wei
    Xiang Peng
    Li Qing-Shan
    [J]. PROCEEDINGS OF THE 2022 INTERNATIONAL CONFERENCE ON CYBER SECURITY, CSW 2022, 2022, : 1 - 9
  • [7] Graph Neural Network Based Anomaly Detection in Dynamic Networks
    Guo, Jia-Yan
    Li, Rong-Hua
    Zhang, Yan
    Wang, Guo-Ren
    [J]. Ruan Jian Xue Bao/Journal of Software, 2020, 31 (03): : 748 - 762
  • [8] Graph neural network approach for anomaly detection
    Xie, Lingqiang
    Pi, Dechang
    Zhang, Xiangyan
    Chen, Junfu
    Luo, Yi
    Yu, Wen
    [J]. MEASUREMENT, 2021, 180
  • [9] Robust Anomaly-Based Insider Threat Detection Using Graph Neural Network
    Xiao, Junchao
    Yang, Lin
    Zhong, Fuli
    Wang, Xiaolei
    Chen, Hongbo
    Li, Dongyang
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (03): : 3717 - 3733
  • [10] Hyperspectral Anomaly Detection Based on a Beta Wavelet Graph Neural Network
    Ruhan, A.
    Shen, Danyao
    Liu, Lijing
    Yin, Juanjuan
    Lin, Renpu
    [J]. IEEE MULTIMEDIA, 2024, 31 (02) : 69 - 79