XG-BoT: An explainable deep graph neural network for botnet detection and forensics

被引:25
|
作者
Lo, Wai Weng [1 ]
Kulatilleke, Gayan [1 ]
Sarhan, Mohanad [1 ]
Layeghy, Siamak [1 ]
Portmann, Marius [1 ]
机构
[1] Univ Queensland, Sch ITEE, Brisbane, Australia
关键词
Graph neural network; Graph representation learning; Botnet detection; Digital forensics; Anomaly detection;
D O I
10.1016/j.iot.2023.100747
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we propose XG-BoT, an explainable deep graph neural network model for botnet node detection. The proposed model comprises a botnet detector , an explainer for automatic forensics. The XG-BoT detector can effectively detect malicious botnet nodes in large-scale networks. Specifically, it utilizes a grouped reversible residual connection with a graph isomorphism network to learn expressive node representations from botnet communication graphs. The explainer, based on the GNNExplainer and saliency map in XG-BoT, can perform automatic network forensics by highlighting suspicious network flows and related botnet nodes. We evaluated XG-BoT using real-world, large-scale botnet network graph datasets. Overall, XG-BoT outperforms state-of-the-art approaches in terms of key evaluation metrics. Additionally, we demonstrate that the XG-BoT explainers can generate useful explanations for automatic network forensics.
引用
收藏
页数:10
相关论文
共 50 条
  • [31] An explainable fast deep neural network for emotion recognition
    Di Luzio, Francesco
    Rosato, Antonello
    Panella, Massimo
    BIOMEDICAL SIGNAL PROCESSING AND CONTROL, 2025, 100
  • [32] Explainable Deep Neural Network for Design of Electric Motors
    Sasaki, Hidenori
    Hidaka, Yuki
    Igarashi, Hajime
    IEEE TRANSACTIONS ON MAGNETICS, 2021, 57 (06)
  • [33] The explainable structure of deep neural network for recommendation systems
    Zanjani, Mohammad Daryaie
    Aghdam, Mehdi Hosseinzadeh
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2024, 159 : 459 - 473
  • [34] Marrying Graph Kernel with Deep Neural Network: A Case Study for Network Anomaly Detection
    Yao, Yepeng
    Su, Liya
    Zhang, Chen
    Lu, Zhigang
    Liu, Baoxu
    COMPUTATIONAL SCIENCE - ICCS 2019, PT II, 2019, 11537 : 102 - 115
  • [35] Botnet detection based on network flow summary and deep learning
    Pektas, Abdurrahman
    Acarman, Tankut
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2018, 28 (06)
  • [36] Stacked recurrent neural network for botnet detection in smart homes
    Popoola, Segun, I
    Adebisi, Bamidele
    Hammoudeh, Mohammad
    Gacanin, Haris
    Gui, Guan
    COMPUTERS & ELECTRICAL ENGINEERING, 2021, 92
  • [37] An efficient botnet detection with the enhanced support vector neural network
    Jagadeesan, S.
    Amutha, B.
    MEASUREMENT, 2021, 176
  • [38] DBoTPM: A Deep Neural Network-Based Botnet Prediction Model
    Haq, Mohd Anul
    ELECTRONICS, 2023, 12 (05)
  • [39] Artificial Neural Network for Bot Detection System in MMOGs
    Prasetya, Kusno
    Da, Wu Zheng
    2010 9TH ANNUAL WORKSHOP ON NETWORK AND SYSTEMS SUPPORT FOR GAMES (NETGAMES 2010), 2010,
  • [40] Image Inpainting Forensics Algorithm Based on Deep Neural Network
    Zhu Xinshan
    Qian Yongjun
    Sun Biao
    Ren Chao
    Sun Ya
    Yao Siru
    ACTA OPTICA SINICA, 2018, 38 (11)