paper-with-me

홈 › Papers

XG-NID: Dual-Modality Network Intrusion Detection using a Heterogeneous Graph Neural Network and Large Language Model

2024-08-27 · Yasir Ali Farrukh, Syed Wali, Irfan Khan, Nathaniel D. Bastian

In the rapidly evolving field of cybersecurity, the integration of flow-level and packet-level information for real-time intrusion detection remains a largely untapped area of research. This paper introduces "XG-NID," a novel framework that, to the best of our knowledge, is the first to fuse flow-level and packet-level data within a heterogeneous graph structure, offering a comprehensive analysis of network traffic. Leveraging a heterogeneous graph neural network (GNN) with graph-level classification, XG-NID uniquely enables real-time inference while effectively capturing the intricate relationships between flow and packet payload data. Unlike traditional GNN-based methodologies that predominantly analyze historical data, XG-NID is designed to accommodate the heterogeneous nature of network traffic, providing a robust and real-time defense mechanism. Our framework extends beyond mere classification; it integrates Large Language Models (LLMs) to generate detailed, human-readable explanations and suggest potential remedial actions, ensuring that the insights produced are both actionable and comprehensible. Additionally, we introduce a new set of flow features based on temporal information, further enhancing the contextual and explainable inferences provided by our model. To facilitate practical application and accessibility, we developed "GNN4ID," an open-source tool that enables the extraction and transformation of raw network traffic into the proposed heterogeneous graph structure, seamlessly integrating flow and packet-level data. Our comprehensive quantitative comparative analysis demonstrates that XG-NID achieves an F1 score of 97\% in multi-class classification, outperforming existing baseline and state-of-the-art methods. This sets a new standard in Network Intrusion Detection Systems by combining innovative data fusion with enhanced interpretability and real-time capabilities.

📄 PDF Abstract BibTeX arXiv:2408.16021

Code (1)

yasir-ali-farrukh/gnn4id 공식 구현 pytorch

Tasks

Graph Neural NetworkIntrusion DetectionLanguage ModelingLanguage ModellingLarge Language ModelMulti-class ClassificationNetwork Intrusion Detection

Methods 이 논문이 사용한 방법론

SET Dynamic Sparse Training method where weight mask is updated randomly periodically
Graph Neural Network 설명 없음

Similar Papers 제목 키워드 기반

Heterogeneous Domain Adaptation for IoT Intrusion Detection: A Geometric Graph Alignment Approach

2023-01-24 · Jiashu Wu, Hao Dai, Yang Wang, Kejiang Ye 외

Data scarcity hinders the usability of data-dependent algorithms when tackling IoT intrusion detection (IID). To address this, we utilise the data rich network intrusion detection (NID) domain to facilitate more accurate…

Domain AdaptationIntrusion DetectionNetwork Intrusion DetectionPseudo Label+1

Graph-based Solutions with Residuals for Intrusion Detection: the Modified E-GraphSAGE and E-ResGAT Algorithms

2021-11-26 · Liyan Chang, Paula Branco

The high volume of increasingly sophisticated cyber threats is drawing growing attention to cybersecurity, where many challenges remain unresolved. Namely, for intrusion detection, new algorithms that are more robust, ef…

Graph AttentionGraph Neural NetworkIntrusion Detection

Adaptive Bi-Recommendation and Self-Improving Network for Heterogeneous Domain Adaptation-Assisted IoT Intrusion Detection

2023-03-25 · Jiashu Wu, Yang Wang, Hao Dai, Chengzhong Xu 외

As Internet of Things devices become prevalent, using intrusion detection to protect IoT from malicious intrusions is of vital importance. However, the data scarcity of IoT hinders the effectiveness of traditional intrus…

Domain AdaptationIntrusion DetectionPseudo LabelRecommendation Systems+1

AutoGraphAD: Unsupervised network anomaly detection using Variational Graph Autoencoders

2025-11-21 · Georgios Anyfantis, Pere Barlet-Ros arxiv

Network Intrusion Detection Systems (NIDS) are essential tools for detecting network attacks and intrusions. While extensive research has explored the use of supervised Machine Learning for attack detection and character…

Unsupervised Anomaly DetectionNetwork Intrusion DetectionContrastive Learning

Accelerating Dependency Graph Learning from Heterogeneous Categorical Event Streams via Knowledge Transfer

2017-08-25 · Chen Luo, Zhengzhang Chen, Lu-An Tang, Anshumali Shrivastava 외

Dependency graph, as a heterogeneous graph representing the intrinsic relationships between different pairs of system entities, is essential to many data analysis applications, such as root cause diagnosis, intrusion det…

Graph LearningIntrusion DetectionTransfer Learning